Need help restoring lost data after nasty virus. Everything hidden.

kdogg

Enlightened
Member
VIP
Local time
3:04 AM
Messages
69
Location
Michigan
I got a nasty virus a few days ago and my MSE and Malwarebytes kept taking care of it but it kept coming back.

Finally my computer crashed and upon reboot, EVERYTHING was gone. By gone my computer would still boot but it was loading a default desktop with ALL my icons gone and when I would try to access my C: drive, it showed that it was completely empty. Looking in "My Computer" the space was still used though.

Next looking at my D: and E: drives (2TB and 3TB WDC's) I found the same issue. My Computer showed the amount of space I expected to see take and free was correct but when I would access them, they were empty like freshly formatted drives.

I fired up a command window and did the following:

attrib -h -r -s /s /d X:\*.*

X being the drive letter in question at the time. This seems to have restored MOST of my folders on my D: and E: drives. However something were still locked out with the following style errors:

Access denied - E:\<Folder Name Here>

Some of the stuff was restored, a ton was not.

Also, some of the folders that were unhidden STILL show as "access denied" when I try to enter/access them. I can get into them as I'm an "admin" on this system but I'm curious as to why I get this error?

How do I just reset all my permissions so it's like it should be if the drive was FRESH.

Thanks!
 

My Computer My Computer

Computer Manufacturer/Model Number
My Own Computer!
OS
Windows 7 Ultimate x64
CPU
AMD Athlon II X2 245 Regor 2.9GHz Socket AM3 65W Dual-Core
Motherboard
ASUS M4A88TD-M/USB3 880G
Memory
Crucial Ballistix Tracer 8GB (4x2GB) DDR3 1600 (PC3 12800)
Graphics Card(s)
ATI Radeon HD3870 X2
Sound Card
Onboard HD Audio
Monitor(s) Displays
Westinghouse 22" LCD, Samsung 46" LCD TV
Screen Resolution
1680x1050, Extended Display Setup
Hard Drives
2x Western Digital 74GB Raptors SATA Raid (OS & Games Drive)
1x Western Digital 1.5TB SATA (Storage)
1x Western Digital 2TB SATA (Storage)
PSU
Antec 550 Watt
Case
Antec Three Hundred
Cooling
3x Antec 120mm Fans & OEM CPU/GPU Coolers
Keyboard
Microsoft Comfort Curve Keyboard 2000
Mouse
Microsoft Bluetooth Explorer Mouse
Internet Speed
Comcastic Cable Internet! When it works!
*Update*

It just hit me... I needed to run the command window as "administrator" before executing the attrib commands to have it restore ALL the folders. OK! All my folders are now visible.

HOWEVER when I click on some of them, I still get access denied before going into them. I'd still like to know WHY that is. I can access them as I'm an admin but it still throws the error before opening them and I have to click continue.

Thanks!
 

My Computer My Computer

Computer Manufacturer/Model Number
My Own Computer!
OS
Windows 7 Ultimate x64
CPU
AMD Athlon II X2 245 Regor 2.9GHz Socket AM3 65W Dual-Core
Motherboard
ASUS M4A88TD-M/USB3 880G
Memory
Crucial Ballistix Tracer 8GB (4x2GB) DDR3 1600 (PC3 12800)
Graphics Card(s)
ATI Radeon HD3870 X2
Sound Card
Onboard HD Audio
Monitor(s) Displays
Westinghouse 22" LCD, Samsung 46" LCD TV
Screen Resolution
1680x1050, Extended Display Setup
Hard Drives
2x Western Digital 74GB Raptors SATA Raid (OS & Games Drive)
1x Western Digital 1.5TB SATA (Storage)
1x Western Digital 2TB SATA (Storage)
PSU
Antec 550 Watt
Case
Antec Three Hundred
Cooling
3x Antec 120mm Fans & OEM CPU/GPU Coolers
Keyboard
Microsoft Comfort Curve Keyboard 2000
Mouse
Microsoft Bluetooth Explorer Mouse
Internet Speed
Comcastic Cable Internet! When it works!
Try this: Take Ownership Shortcut

Copy out your files to external HD now, then run Malwarebytes and AV scans again.

You'll likely need to wipe the HD to clean reinstall Win7 as it's hard to shake off all of the effects and often easier to get a perfect reinstall, backup an image so you only have to do it once.

Reinstalling Windows 7
 
what is/was the name of the 'nasty virus?--maybe it is actually 'nasty' malware--googling 'remove (name)' should allow you to find info on bleepingcomputer for malware removal.

also try downloading and running RKill and unhide

here is one example--with links to 'unhide' and 'RKill'

Remove Windows Recovery (Uninstall Guide)
 

My Computer My Computer

Computer Manufacturer/Model Number
SALEON model 2.2b
OS
win7 ultimate 32bit
CPU
core2 Extreme QX6850-OCd to 3.15 GHz
Motherboard
ASUS P5G41-M LE
Memory
4 GB
Graphics Card(s)
NVidia 8600 GT
Monitor(s) Displays
23" acer
Hard Drives
one SATA 250GB partitioned equally in half
one SATA 160GB-internal storage
PSU
500W Thermaltake
Case
mini tower
Back
Top