Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 25th, 2012, 12:27 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,405
Default Malware recovery

Hi Guys,

I cleaned a 64 bit Win7 machine that had, I believe it was "File Recovery" rogue AV. This rogue removed icons.

1. Used HMP removed rogue <reboot>
2. Went to c:\users\username\appdata\local\temp\smtmp found folders 1 & 4
copied 1 to c:\program data\start menu & 4 I copied to c:\program data\
desktop

many icons did not reappear, desktop & all programs!

3. run UNHIDE still all programs folders were "empty" & not all icons desktop
returned

4. The machine at this point is stable, & quick, many scans, nothing found.

5. With the system stable & quick, I used "System Restore" pre- infected
state.

After system restore all icons back plus, wallpaper restored.

What could I have done to get the icons & settings back, without having to use SR or re-install apps?
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #2  
Old August 25th, 2012, 01:37 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Malware recovery

well you could have tried using the repair section of superantispyware also
you could seek help at malware removal forums
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #3  
Old August 25th, 2012, 01:45 PM
PhantomPhenix's Avatar
PhantomPhenix PhantomPhenix is offline
Infrequent Poster
 
Join Date: Jul 2010
Posts: 26
Default Re: Malware recovery

Hi, please download and scan Rogue killer. Delete any leftover reg keys left behind from infection.

-http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe-

and download unhide to fix the icons and folders.

-http://download.bleepingcomputer.com/grinler/unhide.exe-

Last edited by JRViejo : August 25th, 2012 at 03:24 PM. Reason: De-linked Direct Downloads - JRViejo
  #4  
Old August 25th, 2012, 05:58 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,405
Default Re: Malware recovery

Hi Guys,

The proplem was not removing the rogue. It's fixing the mess after removal. As I stated I did run Unhide.

I'm not sure if SAS can restore the icons + user settings.
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #5  
Old August 26th, 2012, 05:36 PM
mick92z's Avatar
mick92z mick92z is offline
Frequent Poster
 
Join Date: Apr 2007
Location: In the box
Posts: 352
Default Re: Malware recovery

Quote:
Originally Posted by Rico
What could I have done to get the icons & settings back, without having to use SR or re-install apps?
It's easy reading removal guides, however when it comes to dealing with an infected machine,the goal posts seem to move . This is why experts from removal forums are always up to date with the latest tools.
Here is a link, http://malwaretips.com/blogs/remove-...d-check-virus/
in step 7 it gives instructions regarding desktop icons,it may be of use. However the goal posts will move again. I personally think malware removal is a waste of time.Buts thats just my opinion
  #6  
Old August 26th, 2012, 07:55 PM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,047
Default Re: Malware recovery

check the tools on this page

specifically under 'Reverse Malware Damage'
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #7  
Old August 26th, 2012, 08:36 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,405
Default Re: Malware recovery

Hi Mick,

Great post & now two posters providing a link to RogoueKiller, this one is news to me. Normally I would restore (Macrium Reflect) & move on, & never think twice about the bug. I volunteer my time, to a large club 4000 members, that for the most part do not know what a back-up is:

My frustration with this particular machine was:

1. Clean it, works great, but all programs (empty), & background missing. Giving the machine back in this state, would not be appreciated. And I'm not going to reinstall all there apps. so as to fill the 'all programs' list.

2. Malware free, I did SR, which worked. This could be a strategy: remove the infection > then use SR.

3. SAS does not provide the post malware solution that SR does. Perhaps Rogue Killer does, my next rogue, my first app will be roguekiller.

NOTE - In the brief time I've been working for the club, many AV, AS & other removal apps. did not see Rogues, now many solutions rogues. The industry moves fast.

Thanks
Rico
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #8  
Old August 26th, 2012, 08:39 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,405
Default Re: Malware recovery

Hi Guys,

Treehouse: Thank You! Your sig is a GOLDMINE!!!

Thanks
Rico
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #9  
Old August 27th, 2012, 09:13 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,047
Default Re: Malware recovery

Quote:
Originally Posted by Rico
Hi Guys,

Treehouse: Thank You! Your sig is a GOLDMINE!!!

Thanks
Rico
your welcome Reco
__________________
Active@ Disk Image | 10 On-Demand Scanners

 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:50 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums