Hi jezzzzy.
There is much data on this computer that I do not want to lose.
From my first post to you.
Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.
Because of this, I advise you to backup any personal files and folders before you start.
This is exactly why you are advised to back everything up before we start.
This is the last option for invoking the CF backups if you want to try.
Restart your computer
Before Windows loads, you will be prompted to choose which Operating System to start
Use the up and down arrow key to select Microsoft Windows Recovery Console
You must enter which Windows installation to log onto. Type 1 and press enter
At the C:\Windows prompt, type the following bolded text, and press Enter:
DISABLE CAERF
At the next prompt, type the following bolded text, and press Enter:
DISABLE RESTORE
At the next prompt, type the following bolded text, and press Enter:
CD C:\WINDOWS\CONFIG
At the next prompt, type the following bolded text, and press Enter:
REN LSASS.EXE LSASS.EXE.VIR
At the next prompt, type the following bolded text, and press Enter:
CD C:\WINDOWS\SYSTEM32\DRIVERS
At the next prompt, type the following bolded text, and press Enter:
REN RESTORE.SYS RESTORE.SYS.VIR
At the next prompt, type the following bolded text, and press Enter:
CD C:\WINDOWS\ERDNT
At the next prompt, type the following bolded text, and press Enter:
BATCH CFRECOVERY.BAT
At the next prompt, type the following bolded text, and press Enter:
BATCH CFUNDO.DAT (Ignore if there's any error messages)
At the next prompt, type the following bolded text, and press Enter:
CD C:\COMBOFIX
At the next prompt, type the following bolded text, and press Enter:
TYPE DREV.DAT
At the next prompt, type the following bolded text, and press Enter:
TYPE SVCTARGET.DAT
At the next prompt, type the following bolded text, and press Enter
TYPE NDIS_LOG.DAT
At the next prompt, type the following bolded text, and press Enter:
EXIT
Windows should now begin loading.