Solved

Reset Windows 8.1 with full cleanse leaves evil desktop

Posted on 2015-01-26
15
175 Views
Last Modified: 2015-01-27
I had CTB-Locker virus.  Reset this win8.1 box.  Chose the fully cleanse option.  Told it my email address.  Desktop still says "Your personal files are encrypted by CTB-Locker."  

It is displaying a Synced Theme desktop background which is
decrypt all files nwwagfl - a garbage file .

Why is there this garbage file displaying on my desktop after a full reset?
0
Comment
Question by:supportoranges
  • 7
  • 4
  • 4
15 Comments
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
I guess you used a refresh. A refresh does not harm your files, what you see is normal.
Your files are lost unless you choose to pay the ransom, so you could take a setup disk and re-install, this time formatting the partition(s).
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
i did a reset with full cleanse.
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
If you indeed did, than it seems either the cleanse has not succeeded or you re-infected yourself already. Reinstall after formatting.
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
just got off with Microsoft.  it seems the reset even with fully cleanse the drive goes and installs apps afterwards.  pieces like desktop background file and internet explorer bookmarks get put back into appdata.
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
so the reset in windows 8 isn't really as 'clean' as i would have liked.
0
 
LVL 24

Expert Comment

by:VB ITS
Comment Utility
Did you choose the Remove everything and reinstall Windows option or did you opt for to Refresh it?
Reset-Windows-8.1.png
The Remove everything and reinstall Windows option will remove all your personal files and programs and basically wipe it back to its factory default settings if it came with a recovery partition.
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
I did remove everything and reinstall windows.    My understanding from Microsoft is that this does not wipe the partition.  That is why desktop background file and internet explorer favorites of the customer where not initialized.   I am getting the impression while it may reinstall the O/S, it sets aside some personalizations and then puts them back.
This would explain why the desktop image file (which was installed by malware) did not clear.
I have also seen some internet explorer add-ins remain (specificially the awful Vosteran hijacker).
I'm so unhappy with the Windows 8 reset.  Most customers do not have windows media to reinstall as we did in the old days.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 53

Expert Comment

by:McKnife
Comment Utility
0
 
LVL 24

Expert Comment

by:VB ITS
Comment Utility
Are you using a Microsoft account to sign into your Windows 8.1 machine? Perhaps that's how these tidbits keep coming back
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
Sure... of course that could be it.
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
Yes I am using a Microsoft account to sign in.
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 500 total points
Comment Utility
Check what you're syncing with your Microsoft Account.

- Bring up the Charms bar on the right (press Windows + C simultaneously)
- Click on the Settings icon
- Click Change PC Settings at the bottom
- Click OneDrive on the left then click on Sync settings
- Review if/what you have syncing

It sounds like you may have Desktop personalization and Web Browser turned on. Whilst handy, this may explain how your background and IE Favorites and add-ons came back when you logged in with your Microsoft Account.
0
 
LVL 1

Author Comment

by:supportoranges
Comment Utility
Thank you!  I can see from my own machine that the default is ON for all the One Drive Sync Settings.  That explains a lot and I am so happy I asked on Experts-Exchange!
0
 
LVL 1

Author Closing Comment

by:supportoranges
Comment Utility
Awesome.  Thank you!  This clears up a lot.
0
 
LVL 24

Expert Comment

by:VB ITS
Comment Utility
Thank you and very happy to have helped!
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This Micro Tutorial will teach you how to reformat your flash drive. Sometimes your flash drive may have issues carrying files so this will completely restore it to manufacturing settings. Make sure to backup all files before reformatting. This w…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now