"Windows Vista Recovery" malware removal

Victek

New member
Guru
Local time
2:09 PM
Messages
587
A customer picked up the Windows Vista Recovery virus and I could use some help with the removal procedure. I'm currently scanning with a newly created Norton Internet Security bootable CD. The scan takes a while and I don't know yet if it will fully detect and remove the problem. In case you're not familiar with it the virus blocks access to anti-malware apps, hides user data files and is active in SAFE mode. I can't find a way to get to the usual load points, such as "appdata" etc, to see find the virus EXE. I have booted with a rescue CD, but access to folders in the user profile is denied. Is there a removal FAQ for this one? TIA.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 x64Intel Core2 Extreme Q6850 3.00GHz8 GBRadeon R7 260X
Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

Thanks for the reply. As it worked out the Norton Internet Security boot CD was able to find and remove the active malware (which included the TDSS rootkit). Afterward I had control of the desktop and was able to remove the remaining malware traces and undue the registry hacks in stages. In particular I found a tool called "Unhide.exe" which made the user data visible again. This was an interesting mess to unwind.
 

My Computer My Computer

At a glance

Windows 7 x64Intel Core2 Extreme Q6850 3.00GHz8 GBRadeon R7 260X
Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb

Thanks for the reply. As it worked out the Norton Internet Security boot CD was able to find and remove the active malware (which included the TDSS rootkit). Afterward I had control of the desktop and was able to remove the remaining malware traces and undue the registry hacks in stages. In particular I found a tool called "Unhide.exe" which made the user data visible again. This was an interesting mess to unwind.

Thanks for posting back, Vivtek. Those googling for solutions will find this solution. In fact, I ran across this thread in a google search for the Vista Recovery virus to clean up a neighbor's laptop. And thanks to Jacee for her usual efficiency :cool:.

It's what makes it all work!

James
 

My Computer My Computer

At a glance

Win7U 64 RTMQ95508GB GskillASUS|EAH4850/HTDI/1GD3/A
OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
Back
Top