Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Reset Windows 8.1 with full cleanse leaves evil desktop

Posted on 2015-01-26
15
Medium Priority
?
189 Views
Last Modified: 2015-01-27
I had CTB-Locker virus.  Reset this win8.1 box.  Chose the fully cleanse option.  Told it my email address.  Desktop still says "Your personal files are encrypted by CTB-Locker."  

It is displaying a Synced Theme desktop background which is
decrypt all files nwwagfl - a garbage file .

Why is there this garbage file displaying on my desktop after a full reset?
0
Comment
Question by:supportoranges
  • 7
  • 4
  • 4
15 Comments
 
LVL 58

Expert Comment

by:McKnife
ID: 40571601
I guess you used a refresh. A refresh does not harm your files, what you see is normal.
Your files are lost unless you choose to pay the ransom, so you could take a setup disk and re-install, this time formatting the partition(s).
0
 
LVL 1

Author Comment

by:supportoranges
ID: 40571614
i did a reset with full cleanse.
0
 
LVL 58

Expert Comment

by:McKnife
ID: 40571644
If you indeed did, than it seems either the cleanse has not succeeded or you re-infected yourself already. Reinstall after formatting.
0
[Webinar] Database Backup and Recovery

Does your company store data on premises, off site, in the cloud, or a combination of these? If you answered “yes”, you need a data backup recovery plan that fits each and every platform. Watch now as as Percona teaches us how to build agile data backup recovery plan.

 
LVL 1

Author Comment

by:supportoranges
ID: 40571692
just got off with Microsoft.  it seems the reset even with fully cleanse the drive goes and installs apps afterwards.  pieces like desktop background file and internet explorer bookmarks get put back into appdata.
0
 
LVL 1

Author Comment

by:supportoranges
ID: 40571694
so the reset in windows 8 isn't really as 'clean' as i would have liked.
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40571921
Did you choose the Remove everything and reinstall Windows option or did you opt for to Refresh it?
Reset-Windows-8.1.png
The Remove everything and reinstall Windows option will remove all your personal files and programs and basically wipe it back to its factory default settings if it came with a recovery partition.
0
 
LVL 1

Author Comment

by:supportoranges
ID: 40572654
I did remove everything and reinstall windows.    My understanding from Microsoft is that this does not wipe the partition.  That is why desktop background file and internet explorer favorites of the customer where not initialized.   I am getting the impression while it may reinstall the O/S, it sets aside some personalizations and then puts them back.
This would explain why the desktop image file (which was installed by malware) did not clear.
I have also seen some internet explorer add-ins remain (specificially the awful Vosteran hijacker).
I'm so unhappy with the Windows 8 reset.  Most customers do not have windows media to reinstall as we did in the old days.
0
 
LVL 58

Expert Comment

by:McKnife
ID: 40572669
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40572685
Are you using a Microsoft account to sign into your Windows 8.1 machine? Perhaps that's how these tidbits keep coming back
0
 
LVL 58

Expert Comment

by:McKnife
ID: 40572693
Sure... of course that could be it.
0
 
LVL 1

Author Comment

by:supportoranges
ID: 40572700
Yes I am using a Microsoft account to sign in.
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 2000 total points
ID: 40572744
Check what you're syncing with your Microsoft Account.

- Bring up the Charms bar on the right (press Windows + C simultaneously)
- Click on the Settings icon
- Click Change PC Settings at the bottom
- Click OneDrive on the left then click on Sync settings
- Review if/what you have syncing

It sounds like you may have Desktop personalization and Web Browser turned on. Whilst handy, this may explain how your background and IE Favorites and add-ons came back when you logged in with your Microsoft Account.
0
 
LVL 1

Author Comment

by:supportoranges
ID: 40572750
Thank you!  I can see from my own machine that the default is ON for all the One Drive Sync Settings.  That explains a lot and I am so happy I asked on Experts-Exchange!
0
 
LVL 1

Author Closing Comment

by:supportoranges
ID: 40572751
Awesome.  Thank you!  This clears up a lot.
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40572755
Thank you and very happy to have helped!
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes a user will call me frantically, explaining that something has gone wrong and they have tried everything (read - they have messed it up more and now need someone to clean up) and it still does no good, can I help them?!  Usually the standa…
OfficeMate Freezes on login or does not load after login credentials are input.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
This Micro Tutorial will teach you how to reformat your flash drive. Sometimes your flash drive may have issues carrying files so this will completely restore it to manufacturing settings. Make sure to backup all files before reformatting. This w…
Suggested Courses
Course of the Month15 days, 19 hours left to enroll

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question