How to fix damage done by virus

XxsoulwolfxX

New member
Local time
6:56 AM
Messages
21
Currently i removed virus's my brothers computer
and have checked thoroughly using three types of Antivirus

Avira run in: (safe mode and normal mode)
Malewarebytes run in: (safe mode)
MSERT run in: (normal mode)

So i think i have cleared the trojans and adware that infected his desktop
my question to the forum is

How to fix the damage's leftover by the virus

in a quick and efficeant manner


ps: my brother does not have a windows 7 disk to reainstall the OS
because he lost it :confused:
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba
OS
windows vista 32bit
Hi,

What do you mean by "damage"? Which malware did you find?

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
My usual disclaimer: I'm not an expert in anything! :)

The first thing you'd need to know is what (if anything) is damaged. If it's a specific program you could uninstall and then reinstall a fresh copy. If it's a system file you'd have to have access to an installation DVD (either your own or borrowed from someone) to extract a clean copy of the damaged file. The DVD should match your operating system exactly. (If your machine is running 7 Pro 32-bit don't use 7 Home Edition 64-bit, etc.)

http://www.sevenforums.com/tutorials/42776-extract-files-windows-7-installation-dvd.html

You might find this CNET article helpful:

Tutorial: How to repair a malware-damaged PC | CNet Analysis
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
The virus's found (i cant remember there names)

The damage :

The 'C:\' says that there are no files in there despite saying that 244gb of 448 gb is taken some other things are inexesible from the start menu as in there are no icons there that were there before the infection

and windows defender wont start up along with other applications by windows like
eg: updater and firewall
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba
OS
windows vista 32bit
I'm still not an expert in anything! :D

I'd try a System Restore to a date/time prior to the malware being installed. (Providing you have a restore point that goes back that far.) If you can restore the machine I'd again run full scans with Malwarebytes, your resident antivirus / antispyware programs, etc. Don't forget to update the data bases for each.

http://www.sevenforums.com/tutorials/700-system-restore.html

I'd also consider using another free tool from Microsoft called Standalone System Sweeper.

http://www.sevenforums.com/tutorials/166445-microsoft-standalone-system-sweeper.html

I'd also try running a System File Checker scan. If it finds any issues run it three times rebooting in between each scan. Ordinarily Windows 7 will not ask you to insert a disc to replace the files since the system files are stored within Windows 7, unlike in XP where you needed to insert the install media. But if the malware damaged or corrupted the system files SFC probably won't work. In that case you may have to do a Repair Install (perhaps having to borrow an identical install DVD.)

http://www.sevenforums.com/tutorials/1538-sfc-scannow-command-system-file-checker.html

http://www.sevenforums.com/tutorials/3413-repair-install.html

On a personal note, even if you run a dozen malware scans and they all come back clean, and even if you do a system restore or a repair install and everything seems to be working the way it should, you can't be absolutely sure all traces of the malware have been removed. Sometimes you have to go through the hassle and inconvenience of formatting the hard drive and installing everything from scratch. Or using a manufacturer's hidden recovery partition to restore the machine to factory specs.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Good, solid advice from Mars. Seeing as we have no idea of the type/severity of the malware you had, its very difficult to say what fixes you could/should implement and how effective they may be.

Mars suggestions in the last paragraph are spot on : The absolute only sure way to get a clean system is a clean install. If you have lost your Windows installation disk, then you could borrow one of exactly the same type, or you could legitimately download one from a legitimate site - unfortunately the forum rules preclude us from posting a link for that, but some judicious use of Google will help you.

Bear in mind, that depending on what malware you were infected with, any passwords you had stored on your PC should now be considered unsafe - you need to change them on another computer that is safe/clean from malware.

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
My mom had a similar virus to the one described in this thread. I cleaned out the virus, tried making all her folders visible, etc., and the end result was a Windows startup that still showed no taskbar or desktop. The only fix that worked was restoring to factory settings, the near equivalent to reinstalling Windows. Definitely suggest getting ahold of the proper Windows 7 disc, or legally downloading one as suggested from an official site.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
The virus's found (i cant remember there names)

The damage :

The 'C:\' says that there are no files in there despite saying that 244gb of 448 gb is taken some other things are inexesible from the start menu as in there are no icons there that were there before the infection

and windows defender wont start up along with other applications by windows like
eg: updater and firewall

You should be able to locate the name of the removed files in the quarantine log. Guessing that it was one of the family in the FakeHDD type infection that hides startup files, if you didn't delete temp files, Unhide.exe should solve the problem.

There are infections that will hide all the files on your computer from being seen. To make your files visible again, please download the following program to your desktop:

Unhide.exe

Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run.

This program will remove the +H, or hidden, attribute from all the files on your hard drives. It is important to note that if there are any files that were purposely hidden by you, you will need to hide them again after this tool is run.

In the event you cleared the temp files, using the appropriate file your your brother's OS should restore the default start menu:

Windows 7 32-bit US English: http://download.bleepingcomputer.com/grinler/fakehdd/win7-32-sm-reset.exe

Windows 7 X64 US English Windows: http://download.bleepingcomputer.com/grinler/fakehdd/win7-x64-sm-reset.exe
 

My Computer My Computer

OS
Windows 7 & Windows Vista Ultimate
Back
Top