Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Windows Repair virus?  (Read 3289 times)

0 Members and 1 Guest are viewing this topic.

jabarim95

  • Guest
Windows Repair virus?
« on: March 31, 2011, 12:51:21 PM »
Is there any free Trojan scans that are free and get rid of the Windows Repair virus?
- That get rid of it completely....

Spoiler



    Specialist

    Thanked: 50
  • Experience: Beginner
  • OS: Windows XP
Re: Windows Repair virus?
« Reply #1 on: March 31, 2011, 01:08:32 PM »
Whenever I watch TV and I see those poor starving kids all over the world, I can't help but cry. I mean I would love to be skinny like that, but not with all those flies and death and stuff." - Mariah Carey, Pop Singer

jabarimark55



    Newbie

  • Experience: Beginner
  • OS: Unknown
Re: Windows Repair virus?
« Reply #2 on: April 15, 2011, 10:09:25 AM »
I just had that bugger virus...I think I got rid of it (fingers crossed)



I had one problem though: the Windows Repair virus blocks you from updating Malwarebytes, and it replicates itself so that each time you reboot after running Malwarebytes, it's back.

The bleepingcomputer.com guide gives you some simple proprietary software to run: a thing called rkill that stops all running processes, and a thing called unhide that lets you unhide all the files that Windows Repair hides. So the steps the guide gives you are:
1) unhide files manually
2) (download and) run rkill to halt Windows Repair
3) (download and) run Malwarebytes to remove it.
4) run unhide.exe to reset your files as visible files again.

The problem is that after step 3, Malwarebytes reboots your computer and Windows Repair is back.

Here's what worked for me.
1) unhide files manually
2) run rkill to halt windows repair.
3) review the rkill log file and write down the names and file locations of everything it shut down
4) run Malwarebytes
4) When Malwarebytes is done, remove the things it finds but don't reboot the computer.
5) Go into My Computer and manually search for the file names that rkill shut down. You'll see a bunch of files with those names that Malwarebytes missed. Delete them all manually.
6) (Download and) Run CCleaner to clean the registry of all the registry files associated with Windows Repair (they'll pop up in CCleaner as dead registry keys).
7) Reboot
8) You should be able to update Malwarebytes again. I re-ran Malwarebytes and CCleaner again to be safe
9) Run the unhide software from the bleepingcomputer guide to repair the hidden file settings that Windows Repair changes.

That seemed to work for me. All free. I'm running Windows XP home, btw, for what it's worth.