system restore wont let me restore

May 19, 2009 at 18:10:25
Specs: Windows xp
k so i tried to restore my settings with system restore because i got the win32/cryptor so i am gunna try this but when i select my date and go to select next it wont let me doesnt matter how many times i click it says it may take a bit but i waited like 20 mins and it still aint working can some1 help me out?
,thanks brady

See More: system restore wont let me restore

Report •


#1
May 19, 2009 at 18:16:15
Which antivirus detected that?

--------------------------------------------
To Private Message me Click Here


Report •

#2
May 19, 2009 at 18:18:28
avg 8.5

Report •

#3
May 19, 2009 at 18:21:32
AVG didn't fix the virus? Why were you trying to restore? help you out with restore? You can try to restore from recovery console.

--------------------------------------------
To Private Message me Click Here


Report •

Related Solutions

#4
May 19, 2009 at 18:26:43
i did that but it didnt work >.< so yea i tried doing a system restore but yea it wont even let me do that so far ive ran pc-cillin avg and a few other anti viruses but none have gotten this win32/cryptor got any ideas on how to remove him lol says i got 3 but i think they are just clones from the original but yea i dunno

Report •

#5
May 19, 2009 at 18:29:49
Can you please post your AVZ log:

1) To create the logfile, download AVZ by clicking HERE. Please save this file to your desktop or "My Documents" folder.

2) Next, unpack the file to a new folder using the Compressed (zipped) folders wizard built into Windows XP/Vista, or a zip utility of your choice.

3) Once you have unpacked the contents of the zip archive, please launch the file AVZ.exe by double clicking on it or right clicking and selecting Open.
Note: If you are running Windows vista launch AVZ.exe by right clicking and selecting Run as Administrator

You should now see the main window of the AVZ utility. Please navigate to File->Custom Scripts. Copy the script below by using the keyboard shortcut CTRL+C or the corresponding option via right click.

begin
ExecuteStdScr(3);
RebootWindows(true);
end.

Paste the script into the execution window by using CTRL+V keyboard shortcut, or the "paste" option via the right click menu. Click on Run to run the script, the PC will reboot. After the reboot the LOG subfolder is created in the folder with AVZ, with a file called virusinfo_syscure.zip inside. Upload that file to rapidshare.com and paste the link here.

Image Tutorial

--------------------------------------------
To Private Message me Click Here


Report •

#6
May 19, 2009 at 18:35:08
im on my laptop right now so yea but the virus sends me to random sites is there a way you could give me a step to step guide on how to remove it without coming to this site on my other computer i know im being hard but its impossable to get my other computer to go anywere on the web without going to random website

Report •

#7
May 19, 2009 at 18:37:25
Use usb and to transfer between the two computers. Just make sure you scan usb for infection. There are multiple steps involved in cleaning manually. Start with Response Number 5.

--------------------------------------------
To Private Message me Click Here


Report •

#8
May 19, 2009 at 18:40:30
would i be able to send it via e-mail like through hotmail or yahoo?

Report •

#9
May 19, 2009 at 18:56:12
????? no mean to pressure but yea my computer is getting increasingly more slow and has started to beep alot more often

Report •

#10
May 19, 2009 at 19:41:39
Yes you can.

--------------------------------------------
To Private Message me Click Here


Report •

#11
May 19, 2009 at 19:44:12
kk so basically im sending it threw e-mail as an attachment then its gunna restart my comp and bring up the trojan information then im supposta paste it in here

Report •

#12
May 19, 2009 at 19:52:01
email AVZ tool to infected computer > run avz on infected computer > mail back the log from infected computer > upload it to rapidshare > paste the link here.

--------------------------------------------
To Private Message me Click Here


Report •

#13
May 19, 2009 at 20:25:19
k ive done all that but i got 4 diff virusinfo_syscure 2 are zipped folders and 2 are internet based which 1 do i choose?

Report •

#14
May 19, 2009 at 20:28:07
virusinfo_syscure.zip look at the image tutorial in above post.

--------------------------------------------
To Private Message me Click Here


Report •

#15
May 19, 2009 at 20:30:19
yea theres 2 zips theres one with absolutly nothing in it and the other has like 2 or 3 things in it

Report •

#16
May 19, 2009 at 20:31:36
One with 2 things in it.

--------------------------------------------
To Private Message me Click Here


Report •

#17
May 19, 2009 at 20:35:22
k how would i go about sending it through an attachment open it on this comp then send it to you on rapidshare.com

Report •

#18
May 19, 2009 at 20:46:18
the link is http://rapidshare.com/files/2350327...

Report •

#19
May 19, 2009 at 20:49:36
can you figure some steps out how to fix it?

Report •

#20
May 19, 2009 at 21:11:59
Run this script same way as above in AVZ:


begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
 DelBHO('{39fc2065-c9c7-49cd-8942-44cc2dedc844}');
 DelBHO('{07B18EA1-A523-4961-B6BB-170DE4475CCA}');
 DelBHO('{00A6FAF1-072E-44cf-8957-5838F569A31D}');
 QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
 QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
 QuarantineFile('C:\Documents and Settings\HP_Administrator\Application Data\winav.exe','');
 TerminateProcessByName('C:\Documents and Settings\HP_Administrator\Application Data\winav.exe');
 QuarantineFile('C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll','');
 QuarantineFile('C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL','');
 QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe','');
 DeleteService('MyWebSearchService');
 StopService('MyWebSearchService');
 QuarantineFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL','');
 TerminateProcessByName('C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL');
 QuarantineFile('c:\progra~1\mywebs~1\bar\1.bin\m3srchmn.exe','');
 TerminateProcessByName('c:\progra~1\mywebs~1\bar\1.bin\m3srchmn.exe');
 QuarantineFile('C:\WINDOWS\ieocx.dll','');
 QuarantineFile('C:\Program Files\Internet Explorer\MSIMG32.dll','');
 QuarantineFile('\\?\globalroot\systemroot\system32\UACxgpeimrrnngvrrn.dll','');
 QuarantineFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL','');
 QuarantineFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL','');
 QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoestb.dll','');
 DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoestb.dll');
 DeleteFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL');
 DeleteFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL');
 DeleteFile('\\?\globalroot\systemroot\system32\UACxgpeimrrnngvrrn.dll');
 DeleteFile('C:\Program Files\Internet Explorer\MSIMG32.dll');
 DeleteFile('C:\WINDOWS\ieocx.dll');
 DeleteFile('c:\progra~1\mywebs~1\bar\1.bin\m3srchmn.exe');
 DeleteFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL');
 DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe');
 DeleteFile('C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL');
 DeleteFile('C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll');
 DeleteFile('C:\Documents and Settings\HP_Administrator\Application Data\winav.exe');
 DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
 DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

Your computer will reboot after it reboots. Let me know and i will tell you next step.

--------------------------------------------
To Private Message me Click Here


Report •

#21
May 19, 2009 at 21:21:15
k done deal

Report •

#22
May 19, 2009 at 21:24:24
k its not making the beep anymore but winpc antivirus is still on there (thats what the trojan downloaded)

Report •

#23
May 19, 2009 at 21:24:56
Is you internet working now? System much better? Download: superantispyware
Run full system scan fix what it detects and post scan log here at the end.

--------------------------------------------
To Private Message me Click Here


Report •

#24
May 19, 2009 at 21:26:33
yep internets working crisply ill run a full scan then post it

Report •

#25
May 19, 2009 at 21:34:33
but yea ok ill send you the scan log tomorrow i gotta get to bed

Report •

#26
May 19, 2009 at 21:37:02
k wait 1 problem i downloaded it and it gives me the send error report box? that caused by the script you gave me or is that on my part?

Report •

#27
May 19, 2009 at 21:58:33
and it wont let me access my internet games

Report •

#28
May 20, 2009 at 05:17:28
Attach a Combofix log, please review and follow these instructions carefully.

Download it here -> http://download.bleepingcomputer.co...

Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows and pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post.

--------------------------------------------
To Private Message me Click Here


Report •

#29
May 20, 2009 at 14:57:20
how would i go about pausing AVG 8.5

Report •

#30
May 20, 2009 at 15:02:12
AVG 8
Please open the AVG 8 Control Center, by right clicking on the AVG 8 icon on task bar.

* Click on Tools.
* Select Advanced.
* In the left hand pane, scroll down to "Resident Shield".
* In the main pane, deselect the option to "Enable Resident Shield."
To re-enable AVG 8, please select "Enable Resident Shield" again.

--------------------------------------------
To Private Message me Click Here


Report •

#31
May 20, 2009 at 15:14:03
k i re nemed the file like you said and it did its thing till after the reboot and it gave me an alert saying that the file was compromised and that i needed to re-install that program from the website and it kept telling me to send error it said it about 3 or 4 times is it suppost to do that?

Report •

#32
May 20, 2009 at 15:16:42
Did it finish or not? You see the log file? Please post a screenshot.

--------------------------------------------
To Private Message me Click Here


Report •

#33
May 20, 2009 at 15:18:09
no log file theres nothing on the screen but my icons if you need a screenshot gimmie 10 seconds

Report •

#34
May 20, 2009 at 15:22:15
You are seriously infected and even if we can clean up most of the malware, your system may still be compromised. You have a choice of saving your data to a disc and doing a complete reformat and re-install or we can continue with the fixes and see just how bad or good we end up.

--------------------------------------------
To Private Message me Click Here


Report •

#35
May 20, 2009 at 15:26:09
k so if we continue what would be lost? everything that i had downloaded for example windows messanger or would it be everything period?

Report •

#36
May 20, 2009 at 15:34:01
Best way is to Make antivirus boot disk and scan your PC from it. Take a look at this link: http://www.raymond.cc/blog/archives... That way damage might be minimal to ur data.

--------------------------------------------
To Private Message me Click Here


Report •

#37
May 20, 2009 at 15:37:43
k i read that so what you want me to do is download it and let it do its thing but you talked about saving my data to a disk and reformat what kind of disk would i need to do that

Report •

#38
May 20, 2009 at 15:38:56
What do you have microsoft windows xp installed?

--------------------------------------------
To Private Message me Click Here


Report •

#39
May 20, 2009 at 15:39:40
yes i have that

Report •

#40
May 20, 2009 at 15:40:47
What kind of data you want to save?

--------------------------------------------
To Private Message me Click Here


Report •

#41
May 20, 2009 at 15:43:43
lol everything i absolutly need and if possable some of the programs that arnt effected by the trojan

Report •

#42
May 20, 2009 at 15:47:44
Don't really know effect of spread. See if you can scan from bootdisk and run combofix you might be able to salvage current installation. You also have take into account reinfection when u backup stuff from infected drive. Try asking in: http://www.computing.net/forum/wind...

--------------------------------------------
To Private Message me Click Here


Report •

#43
May 20, 2009 at 15:50:55
what should i be asking about?

Report •

#44
May 20, 2009 at 15:51:44
One more thing before we move on to other solutions. Boot into Safemode with networking. Re-download combofix again and try to run it. Also try to just boot into safe mode and transfer it via usb.

--------------------------------------------
To Private Message me Click Here


Report •

#45
May 20, 2009 at 15:55:21
lol ummm yea how do i boot into safe mode

Report •

#46
May 20, 2009 at 15:59:12
* If the computer is running, shut down Windows, and then turn off the power
* Wait 30 seconds, and then turn the computer on.
* Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
* Ensure that the Safe mode or Safe mode with networking option is selected.
* Press Enter. The computer then begins to start in Safe mode.

--------------------------------------------
To Private Message me Click Here


Report •

#47
May 20, 2009 at 16:20:14
k i think it worked this time im just waiting for the log to close itself out so it can be located

Report •

#48
May 20, 2009 at 16:22:26
k i white box with a bunch of my information on it poped up what do i do?

Report •

#49
May 20, 2009 at 16:30:06
Did your computer reboot by itself? Please read Response Number 28 carefully and attach that file to rapidshare.com and post a link.

--------------------------------------------
To Private Message me Click Here


Report •

#50
May 20, 2009 at 16:37:57
heres the link http://rapidshare.com/files/2353974...

Report •

#51
May 20, 2009 at 16:42:06
Wrong file... Read carefully please.

--------------------------------------------
To Private Message me Click Here


Report •

#52
Report •

#53
May 20, 2009 at 16:52:43
is that the right 1?

Report •

#54
May 20, 2009 at 17:16:40
Yes that's the one. Run this in AZV script like before in normal mode:


begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\Program Files\RngInterstitial.dll','');
QuarantineFile('c:\windows\LMI93.tmp','');
DeleteFile('c:\windows\LMI93.tmp');
DeleteFile('C:\Program Files\RngInterstitial.dll');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteRepair(1);
ExecuteRepair(2);
ExecuteRepair(5);
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
ExecuteRepair(10);
ExecuteRepair(14);
ExecuteRepair(15);
BC_Activate;
RebootWindows(true);
end.

Once your Computer reboots. Follow:

Download and run Kaspersky AVP tool:

http://devbuilds.kaspersky-labs.com...

Once you download and start the tool select all the objects/places to be scanned and hit Scan. Fix what it detects and at the end of the scan post screen shot/log of detected items that is fixed and which it could not fix.

--------------------------------------------
To Private Message me Click Here


Report •

#55
May 20, 2009 at 17:41:57
k ill post when its done scanning its gunna take about an hour or 2

Report •

#56
May 20, 2009 at 19:35:33
k so far there have bine 31 reported and its only about 50% done lol anything i can do to rilli slow them down cause right now there all cloning

Report •

#57
May 20, 2009 at 19:40:41
Nothing let it run do its job. Post screenshot of detected window of whatever it found uptill now. Don't stop the scanning or you will have to start all over again.

--------------------------------------------
To Private Message me Click Here


Report •

#58
May 20, 2009 at 19:43:50
k so im gunna have to wait but you want me to post a screen shot right now?

Report •

#59
May 21, 2009 at 19:16:55
Once its done.

--------------------------------------------
To Private Message me Click Here


Report •


Ask Question