Sign in with
Sign up | Sign in
Your question
Closed

Recovery after a virus

Last response: in Windows XP
Share
June 22, 2011 5:44:01 PM

My PC has been attacked by a virus today which hid my desktop, start menu, and D:\ partition files.
I've dealt with the virus and eradicated it with Malwarebytes Anti-Malware, but unluckily the hidden files remained hidden.
I managed to unhide the files on my D:\ partition and desktop(Many of the desktop shortcuts are gone though) and all the folders in the start menu, but many of the folders inside the start menu are empty(I couldn't even access System Restore without accessing it within the System32 folder).

My question is, will System Restore bring back and show the files in the start menu?

More about : recovery virus

Best solution

June 22, 2011 5:49:53 PM

Yes. It should. However, it will also uninstall programs that were added since the restore. It could potentially resurrect the virus as well.

Look up the name of the virus and if it is popular, there may be a restore utility already.
Share
June 22, 2011 6:00:38 PM

Thanks, and my latest restoration point is set to yesterday so I won't have to worry about a bunch of programs going missing.

I'll scan my computer again once I restore it to make sure the virus is gone, also I did look for the virus but there were no restoration utilities being offered other than what I used to unhide the files that were hidden.
Score
0
Related resources
June 22, 2011 6:07:41 PM

You Should use Microsoft Essential Anti Virus its very good Antivirus and it auto Create the Restore Point before Removing Virus so now it's better for you .
Score
0
June 22, 2011 6:19:04 PM

Yeah thanks, I'm most likely going to switch, Avira has certainly let me down on this.
Score
0
June 22, 2011 7:27:15 PM

Hey guys thanks, it worked and restored everything just fine, I have another problem though, don't know if it belongs in this forum.

Since I removed the virus with MBAM and restarted my PC, an IEXPLORE.EXE process appears to open up by itself for whatever reason(I don't use IE). Even when I terminate the process it opens up again after a bit of time, so I suspect it to be a virus.

Thing is, I've scanned my PC again with MBAM and Spybot, and not threats have been found, any idea what causes this/how to fix this and get it out of my system?
Score
0
Anonymous
June 22, 2011 7:47:28 PM

All the free AV programs DO NOT stop this mal-ware from China. NIS 2010 is the only one I've seen that blocks it. I clean up 10 - 20 computers a week, so I know what I'm talking about.
Score
0
June 22, 2011 8:30:37 PM

Quote:
All the free AV programs DO NOT stop this mal-ware from China. NIS 2010 is the only one I've seen that blocks it. I clean up 10 - 20 computers a week, so I know what I'm talking about.


Well gee, there has to be a different solution than that, I'll wait for other responses.
I've installed MSE and I'm doing a full scan currently, the quick scan produced no results.
Score
0
Anonymous
June 22, 2011 9:08:35 PM

Sorry, but free AV programs are worthless. MSE DOES NOT stop Chinese malware.
Score
0
June 22, 2011 10:04:05 PM

Well Grumpy, I wish I was still cleaning up PCs en mass. I had a nice gig doing so and now I don't touch them often so I lost a lot of up-to-date knowledge.

WallJump, Here is the standard process for PC shops.

Download all the respectable Free and trial bits of antivirus softwares and Antispyware applications. NONE of them will clear 100% so it is often required to use a handful. The shop I ran used 8 anti-spyware tools for removal as standard.

<--- The IE process can be traced with a tool call process explorer.--->
http://technet.microsoft.com/en-us/sysinternals/bb89665...

This will get you an idea towards what is causing the process to launch, who is the owner, and what files are associated with it. After that, there are other tools to go further, but as you do, the complexity increases and its hard to really give lessons via forum.

Score
0
July 2, 2011 1:24:06 PM

Best answer selected by WallJump.
Score
0
July 14, 2011 4:15:53 PM

This topic has been closed by Area51reopened
Score
0
!