WIndows Recovery infection

Posted on 2011-04-21
Last Modified: 2012-05-11
One of our PCs is infected with Windows Recovery. I followed the removal instruction from BleepingComputer and was able to stop the pop-up. The problem now I'm getting Google redirection and all my programs do not show up on the Start menu.

I installed Avast AV and it found several things and deleted those, but it's still doing the Google redirection. Right now I'm running Combo Fix in Safe Mode with Networking. Any idea if this doesn't work? ComboFix can't run on a normal Windows boot
Question by:coronoahcoro
    LVL 1

    Expert Comment

    One more scan using Malwarebytes might kill the infection once and for all.
    LVL 7

    Expert Comment

    I agree, Malwarebytes is excellent as well as Hitmanpro.  Both of these are very effective, fast and easy to use.
    LVL 23

    Accepted Solution

    "...ComboFix can't run on a normal Windows boot..."

    It needs to. You must stop the rogue processes so that scanners can run, using Rkill or RogueKiller.

    Download Rkill:

    Download all seven names/extensions and keep trying them until one works. Or try RogueKiller. Great article here:

    Download a fresh copy of Combofix (use a clean computer if need be) and be sure to RENAME it before you download it. Put "xifobmoc.exe" or something in the file name box, and download to a flashdrive or to the infected pc.  Do thesame with Malwarebytes:

    Update and run it in normal mode.  Post the scan logs here for review.

    LVL 47

    Assisted Solution

    Run this tool to remove the hidden flags on files and folders.

    Or, RogueKiller, option 6 to remove hidden flags on files/folders.

    Then run TDSSKiller if you haven't yet adn attach the log.
    LVL 47

    Expert Comment

    Also if you have already run ComboFix can you attach the log here for us to check.
    LVL 23

    Expert Comment

    Glad your problem is resolved.

    Don't forget to uninstall Combofix. Start - Run - (or Windows Key + R ) - type:

    combofix /uninstall

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    There are many reasons malware will stay around and continue to grow as a business.  The biggest reason is the expanding customer base.  More than 40% of people who are infected with ransomware, pay the ransom.  That makes ransomware a multi-million…
    Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now