I've had it up to HERE with this Windows Recovery virus today. Long story short, I had a customer come in with a XP Dell desktop with an easy scareware av variant. I cleaned the whole pc, Combofix the full meal deal and it was running great. They take it home open their email and doing who knows what and withing 20 minutes of leaving my office, they have reinfected it. They say it's the identical virus. So I'm 2nd guessing myself and I tell them I'll clean it for free just to be nice. They bring it in and it's the Windows Recovery virus....NOT what they had before. GRRRR! So I follow the step by step instructions here and it all seems to go well until I try to install a new version of McAfee for them (their request). The install keeps crashing when it gets to the actual installation process. It seems really strange and I'm thinking the machine might still be infected, but everything comes up clean. Everything.
I then realize that the Start Menu folders are mostly empty. Some of the things are there, but not most. All the MS folders are empty, MS Works, Games, Accessories etc as well as 90% of the software apps they've installed. I go through every trick in the book I read here and other places to get those programs to show back up. Nothing. I checked All Users and they were missing there too which (according to the guys on Bleeping Computer) is pretty bad. I tried all their tricks still nothing. So after about 4 more (free) hours into this thing I say screw it and I call the customer, tell them the dilemma they say to nuke if I need to because they have no docs or files on it. They use webmail, play solitaire and that's it.
This has been a pain in the rear and I'm sure one of you guys with more knowledge could have gotten it figured out, but I was at my wits end. I hate giving up and nuking and paving but I've got so many hours in this thing and I'm coming up against a long weekend and they need it back tomorrow. I feel like a quitter, but I guess sometimes I've got to admit defeat and do what makes the most sense economically.