Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Repair Files Deleted by Malwarebytes?  (Read 12754 times)

0 Members and 1 Guest are viewing this topic.

JohnProverbs

    Topic Starter


    Greenhorn

    • Experience: Beginner
    • OS: Unknown
    Repair Files Deleted by Malwarebytes?
    « on: January 12, 2012, 06:34:11 PM »
    Good Day Computer Hope Mods and Users!

    I'm new to the forum and an amateur geek.   I have a problem with my laptop.  It's running Vista Home Premium and I had gotten a virus.  The virus makes copies of shorcuts of every file that is not an exe extension.  Then it makes the folders and files hidden.  I have removed this virus before on my xp system but with vista I can't.   I ran Malwarebytes and had 11 infections.  One of the files was lsass.exe. 

    I made the stupid mistake of just clicking next when it warned me it would delete files.  I did this before on my xp system and it always worked alright.  The system asked for reboot to remove the files and I clicked ok.  After it rebooted I get the welcome screen but I have no desktop.  There's only a blank blue screen with a mouse pointer.

    When I press clt alt delete I get 4 options logoff, switch user, etc.  I have tried to reboot in safemode.  I get the same blank blue screen.  I also have tried the last good configuration 2 times and it still does not load.

    I downloaded the otlpe file and have used it on the computer.  It loads fine thank God. 

    I believe that the 11 files malwarebytes quarantined and/or deleted after I restarted caused the problem.  How can I repair these files?

    I have checked for a restore point and in the repair system options windows said there was no restore points.

    Thanks very much in advance for all your help.  It is greatly appreciated.


    Geek-9pm


      Mastermind
    • Geek After Dark
    • Thanked: 1026
      • Gekk9pm bnlog
    • Certifications: List
    • Computer: Specs
    • Experience: Expert
    • OS: Windows 10
    Re: Repair Files Deleted by Malwarebytes?
    « Reply #1 on: January 12, 2012, 06:48:28 PM »

    JohnProverbs

      Topic Starter


      Greenhorn

      • Experience: Beginner
      • OS: Unknown
      Re: Repair Files Deleted by Malwarebytes?
      « Reply #2 on: January 12, 2012, 06:56:41 PM »
      Thanks for the reply.  I did try this.  I choose the automatic repair option and it said it couldn't repair the system.  How would I manual restore the files if I had the installation disc?

      Geek-9pm


        Mastermind
      • Geek After Dark
      • Thanked: 1026
        • Gekk9pm bnlog
      • Certifications: List
      • Computer: Specs
      • Experience: Expert
      • OS: Windows 10
      Re: Repair Files Deleted by Malwarebytes?
      « Reply #3 on: January 12, 2012, 07:51:30 PM »
      Yes, you can find the compressed file on the original install disc.
      But this is the forum where only the  experts can post. I just responded to see if that was a quick answer.

      The long way to do this requires help from one of the experts. The lsass.exe is a very important file and it is unlikely the Malwarebytes would delete the real one. My gut feeling is that you still have the virus and I an not qualified to walk you through the steps.

      Wait for an expert to come here and take over.

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Repair Files Deleted by Malwarebytes?
      « Reply #4 on: January 12, 2012, 08:00:52 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
      *************************************************************************
      MBAM is a safe product to use. It does not remove essential files. What you're seeing is the results of malware.

      Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
      Save Rkill to your desktop.

      There are 7 different versions. If one of them won't run then download and try to run the other one.
       
      Vista and Win7 users need to right click Rkill and choose Run as Administrator
       

      You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

      * Rkill.exe
      * Rkill.com
      * Rkill.scr
      * WiNlOgOn.exe
      * uSeRiNiT.exe
      * iExplore.exe
      * eXplorer.exe
      Once you've gotten one of them to run then try to immediately run the following.
      ********************************************************
      • Please download Unhide by Grinler from here and save it to your desktop.
      • Double click unhide.exe to run the tool.
      • It will take some time to go through all your files, so please be patient.
      • If this tool doesn´t fix the problem, please let me know.
      ******************************************************
      Download DDS from HERE or HERE and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.
      * Save both reports to your desktop.
      * The instructions here ask you to attach the Attach.txt.



      1) DDS.txt
      2) Attach.txt
      Instead of attaching, please copy/past both logs into your Thread

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copying and pasting it into the reply.

      •Close the program window, and delete the program from your desktop.

      Please note: You may have to disable any script protection running if the scan fails to run.
      After downloading the tool, disconnect from the internet and disable all antivirus protection.
      Run the scan, enable your A/V and reconnect to the internet.
      Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
      Windows 8 and Windows 10 dual boot with two SSD's

      JohnProverbs

        Topic Starter


        Greenhorn

        • Experience: Beginner
        • OS: Unknown
        Re: Repair Files Deleted by Malwarebytes?
        « Reply #5 on: January 12, 2012, 10:10:44 PM »
        Thanks Dave for the help.  I really appreciate you taking the time and energy to do this.  I downloaded all the programs you asked me to and burned them to a dvd.  I will try them and get back to you on if it worked.  Thanks again. :)

        JohnProverbs

          Topic Starter


          Greenhorn

          • Experience: Beginner
          • OS: Unknown
          Re: Repair Files Deleted by Malwarebytes?
          « Reply #6 on: January 13, 2012, 12:03:24 AM »
          I decided to run the hp recovery program that reinstalls the o/s.  It's working now.   I was able to use OTPLE to see the shortcuts for the virus and delete them.  I ran unhide program and rkill. I still don't see the files but I am deciding to end this topic.  Thanks for your help :)

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Repair Files Deleted by Malwarebytes?
          « Reply #7 on: January 13, 2012, 01:06:28 PM »
          You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
          Windows 8 and Windows 10 dual boot with two SSD's