Windows 7 Forums


Windows 7: "Windows Vista Recovery" malware removal

17 May 2011   #1

Windows 7 x64
 
 
"Windows Vista Recovery" malware removal

A customer picked up the Windows Vista Recovery virus and I could use some help with the removal procedure. I'm currently scanning with a newly created Norton Internet Security bootable CD. The scan takes a while and I don't know yet if it will fully detect and remove the problem. In case you're not familiar with it the virus blocks access to anti-malware apps, hides user data files and is active in SAFE mode. I can't find a way to get to the usual load points, such as "appdata" etc, to see find the virus EXE. I have booted with a rescue CD, but access to folders in the user profile is denied. Is there a removal FAQ for this one? TIA.


Last edited by Victek; 17 May 2011 at 12:12 PM..
My System SpecsSystem Spec

17 May 2011   #2

Windows 7 Ultimate 32bit SP1
 
 

See if the manual removal instructions here, will help Windows Vista Recovery and Windows 7 Recovery - Virus Solution and Removal
My System SpecsSystem Spec
19 May 2011   #3

Windows 7 x64
 
 

Quote   Quote: Originally Posted by Jacee View Post
See if the manual removal instructions here, will help Windows Vista Recovery and Windows 7 Recovery - Virus Solution and Removal
Thanks for the reply. As it worked out the Norton Internet Security boot CD was able to find and remove the active malware (which included the TDSS rootkit). Afterward I had control of the desktop and was able to remove the remaining malware traces and undue the registry hacks in stages. In particular I found a tool called "Unhide.exe" which made the user data visible again. This was an interesting mess to unwind.
My System SpecsSystem Spec
.


07 Jun 2011   #4

Win7U 64 RTM
Ellesmere Island
 
 

Quote   Quote: Originally Posted by Victek View Post
Quote   Quote: Originally Posted by Jacee View Post
See if the manual removal instructions here, will help Windows Vista Recovery and Windows 7 Recovery - Virus Solution and Removal
Thanks for the reply. As it worked out the Norton Internet Security boot CD was able to find and remove the active malware (which included the TDSS rootkit). Afterward I had control of the desktop and was able to remove the remaining malware traces and undue the registry hacks in stages. In particular I found a tool called "Unhide.exe" which made the user data visible again. This was an interesting mess to unwind.
Thanks for posting back, Vivtek. Those googling for solutions will find this solution. In fact, I ran across this thread in a google search for the Vista Recovery virus to clean up a neighbor's laptop. And thanks to Jacee for her usual efficiency .

It's what makes it all work!

James
My System SpecsSystem Spec
Reply

 "Windows Vista Recovery" malware removal problems?



Thread Tools



Similar help and support threads for: "Windows Vista Recovery" malware removal
Thread Forum
Can't create recovery media "Windows 7 only allows one copy" Installation & Setup
Sony vaio recovery Problem - "Windows setup can't " Installation & Setup
Solved "Windows failed to start..." Recovery disk is unable to recover Win. BSOD Help and Support
Windows Vista/7 "Working In Background/"Busy" Cursor NO General Discussion
Microsoft: Malware can disable UAC in Windows 7 "by design" News


All times are GMT -5. The time now is 03:00 AM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd