Reset Windows 8.1 with full cleanse leaves evil desktop

I had CTB-Locker virus.  Reset this win8.1 box.  Chose the fully cleanse option.  Told it my email address.  Desktop still says "Your personal files are encrypted by CTB-Locker."  

It is displaying a Synced Theme desktop background which is
decrypt all files nwwagfl - a garbage file .

Why is there this garbage file displaying on my desktop after a full reset?
LVL 1
supportorangesAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
VB ITSConnect With a Mentor Specialist ConsultantCommented:
Check what you're syncing with your Microsoft Account.

- Bring up the Charms bar on the right (press Windows + C simultaneously)
- Click on the Settings icon
- Click Change PC Settings at the bottom
- Click OneDrive on the left then click on Sync settings
- Review if/what you have syncing

It sounds like you may have Desktop personalization and Web Browser turned on. Whilst handy, this may explain how your background and IE Favorites and add-ons came back when you logged in with your Microsoft Account.
0
 
McKnifeCommented:
I guess you used a refresh. A refresh does not harm your files, what you see is normal.
Your files are lost unless you choose to pay the ransom, so you could take a setup disk and re-install, this time formatting the partition(s).
0
 
supportorangesAuthor Commented:
i did a reset with full cleanse.
0
Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

 
McKnifeCommented:
If you indeed did, than it seems either the cleanse has not succeeded or you re-infected yourself already. Reinstall after formatting.
0
 
supportorangesAuthor Commented:
just got off with Microsoft.  it seems the reset even with fully cleanse the drive goes and installs apps afterwards.  pieces like desktop background file and internet explorer bookmarks get put back into appdata.
0
 
supportorangesAuthor Commented:
so the reset in windows 8 isn't really as 'clean' as i would have liked.
0
 
VB ITSSpecialist ConsultantCommented:
Did you choose the Remove everything and reinstall Windows option or did you opt for to Refresh it?
Reset-Windows-8.1.png
The Remove everything and reinstall Windows option will remove all your personal files and programs and basically wipe it back to its factory default settings if it came with a recovery partition.
0
 
supportorangesAuthor Commented:
I did remove everything and reinstall windows.    My understanding from Microsoft is that this does not wipe the partition.  That is why desktop background file and internet explorer favorites of the customer where not initialized.   I am getting the impression while it may reinstall the O/S, it sets aside some personalizations and then puts them back.
This would explain why the desktop image file (which was installed by malware) did not clear.
I have also seen some internet explorer add-ins remain (specificially the awful Vosteran hijacker).
I'm so unhappy with the Windows 8 reset.  Most customers do not have windows media to reinstall as we did in the old days.
0
 
McKnifeCommented:
0
 
VB ITSSpecialist ConsultantCommented:
Are you using a Microsoft account to sign into your Windows 8.1 machine? Perhaps that's how these tidbits keep coming back
0
 
McKnifeCommented:
Sure... of course that could be it.
0
 
supportorangesAuthor Commented:
Yes I am using a Microsoft account to sign in.
0
 
supportorangesAuthor Commented:
Thank you!  I can see from my own machine that the default is ON for all the One Drive Sync Settings.  That explains a lot and I am so happy I asked on Experts-Exchange!
0
 
supportorangesAuthor Commented:
Awesome.  Thank you!  This clears up a lot.
0
 
VB ITSSpecialist ConsultantCommented:
Thank you and very happy to have helped!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.