I have run through the steps for removing Data Restore again (running MBAM right now), but so far it hasn't found anything. I haven't had a chance to try running UNHIDE in safe mode, or stuff like that. I am mostly wondering if others have had experience with this being a left-over symptom of Data Restore, or and indication that I have something more serious.
OK, some progress...sort of.
I found a description of Unhide.exe (http://www.bleepingcomputer.com/forums/topic405109.html) and went to the temp folders they describe and copied them over. I still had many things that were showing as "(empty)" when I thought that they shouldn't be. So I dug around and manually looked at those folders in the TEMP dir and yes, they were empty there, too. So I searched for the content that I THOUGHT should be there, and in many cases, it wasn't there either. OK, fine, I don't have a photographic memory of my Start Menu.
But what I didn't find in the TEMP folders were the copies that correspond to my Quick Launch/Pinned items, and I KNOW that I did have many of those. I use them everyday. So those are missing, although rather easy to recreate (but annoying).
Second item is that SOME folders SHOULD have stuff in them, like Administrative Tools. That shows as "(empty)" on both the Browse list on the left side of the Start menu, as well as the "System" side of the start menu on the right. (I have it configured to show up in both places.) Going to that directory through the Control Panel also reveals that it is empty. So they are apparently correct in showing it as empty, but where did they go? If you go into Control Panel -> System & Security, Admin Tools is listed as a category, with 4 or 5 options showing there. Clicking those DOES cause them to launch, but clicking on the "Administrative Tools" link to go into the full list of tools reveals an empty folder.
And the last thing, I had a Windows Update that ran a few days before this all started, and I thought to try and use that to restore things. But it doesn't show on my list. The only restore points are the ones that I have managed to get to run just yesterday, after all this infection started. Curiously, my Update History does show that I had some successful Updates made in that time frame I mentioned (a few days before this started).
Oh, and yes, I have managed to get Update to work; I just had to wait for it the fully complete. The progress meter never metered. But it eventually finished.
Edited by boopme, 12 October 2011 - 12:04 PM.