Windows Restore - Malware Virus

gtd2000

Platinum Member
Oct 22, 1999
2,731
0
76
My mother has reliably informed me that her computer has the "Windows Restore" virus - I've been trying to help her remotely after reading some solutions on the net which generaly include downloading a program called RKill and once it's done its magic running Malwarebytes.

Per this link:
http://www.bleepingcomputer.com/virus-removal/remove-windows-restore

So far nothing seems to be working to get rid of this bloody problem - have any of you guys come across this virus/malware and a solution?

Cheers in advance
 

Matt1970

Lifer
Mar 19, 2007
12,320
3
0
All those sites tell you to run MalwareBytes but none of them tell you how you need to run it. 99% of the time you can't run it in normal mode, you need to reboot in safe mode. 99% of the infections will be blocked from running in safe mode. If they are running in safe mode, you need to kill the associated process, download Malwarebytes but you need to rename it as it saves, then run it as administarator. I usually rename it something like "Lappy"

Nopw reboot in normal mode and remove any proxy settings for your LAN. Then run Spybot and then Super Anti-Spyware.
 

gtd2000

Platinum Member
Oct 22, 1999
2,731
0
76
Yeah we took the safe mode route from the beginning but the virus still runs.

It seems to block out desktop icons and if you go to the programs via the start button nothing is listed.

I did manage to get malwarebytes running by telling my mother to browse for it through My Computer, however, it appears that this virus has now learned this technique and she can't do it any more

Unfortunately, my mother is not particularly good with PC's and you need to tell her everything about 10 times before she actually does it and then continually wants to read everything back to me.....groan!!!

Fortunately this is a PC that has more than one user account and the virus seems to have only infected her account.

Thanks for the suggestions - I'll do some reading over lunch
 

lowrider69

Senior member
Aug 26, 2004
422
0
0
Worse comes to worse pull the drive out of her machine and hook it up to another machine, take ownership of the drive and scan from there. Fortunately I haven't had to do that in a while because the removal tools have gotten better over the years. But years ago I had to do it all of the time.
 

gtd2000

Platinum Member
Oct 22, 1999
2,731
0
76
Well so far it appears that the virus has been killed - the often ignored step to getting the thing killed is to make sure you turn off the real System Restore on all drives, otherwise it just keeps coming back.

Now that the virus has been removed there is still a problem to view the contents of the start/programs menu as it's now all blank.

I've told my mother to make sure the view all hidden files option has been selected but she still has virtually all of her desktop icons missing.

Looks like further reading is required over the weekend after work.
 

Matt1970

Lifer
Mar 19, 2007
12,320
3
0
1. Right click on the Start Button
2. Click Properties
3. In the Start Menu Properties window click “customize”
4. Click on the “Use Default Settings” button
5. Click “Ok”
6. Click “Apply”

If the programs in start menu are still missing and only missing in your mom's account, just create a new accound and transfer doc&pics.
 

gtd2000

Platinum Member
Oct 22, 1999
2,731
0
76
1. Right click on the Start Button
2. Click Properties
3. In the Start Menu Properties window click “customize”
4. Click on the “Use Default Settings” button
5. Click “Ok”
6. Click “Apply”

If the programs in start menu are still missing and only missing in your mom's account, just create a new accound and transfer doc&pics.

Cheers for the advise Matt but in XP the options appeared to be different without the USE Default Settings button - at least that's what my mum said anyway

I got her to download a program called Unhide.exe and fortunately all is now well with her account again.


Thanks for all the help and suggestions guys
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |