# "Windows Vista Recovery" Virus

**URL:** <https://boards.straightdope.com/t/windows-vista-recovery-virus/583921>\
**Category:** Factual Questions\
**Created:** [June 1, 2011, 2:18am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921 "2011-06-01T02:18:57Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![SanDiegoTim](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@SanDiegoTim](https://boards.straightdope.com/u/SanDiegoTim)\
**Post date:** [June 1, 2011, 2:18am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/1 "2011-06-01T02:18:57Z")

</div>

Anyone heard of this virus? My understanding it’s new. Any fixes? My up-to-date virus protection program (Trend Micro) didn’t catch it.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 1, 2011, 2:35am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/2 "2011-06-01T02:35:26Z")

</div>

It can be associated with the TDSS/Alureon rootkit, so it can be a real stinker to remove.

I have always had good results with the removal guides at [bleepingcomputer.com](http://bleepingcomputer.com):

[Remove Windows Vista Recovery (Uninstall Guide)](http://www.bleepingcomputer.com/virus-removal/remove-windows-vista-recovery)

---

<div class="post-metadata">

**Author:** ![needscoffee](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/needscoffee/32/1076_2.png) [@needscoffee](https://boards.straightdope.com/u/needscoffee)\
**Post date:** [June 1, 2011, 3:47am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/3 "2011-06-01T03:47:23Z")

</div>

My daughter got it on her computer Friday night. From [other threads](http://boards.straightdope.com/sdmb/showthread.php?t=607641) here, I learned that you can often log in as a different user and be able to get around the virus/Trojan in order to run a program to get rid of it. That worked in this case; I was able to log in as administrator with no virus popup. Boot up in _Safe Mode_ or _Safe Mode With Networking_ first (F8). My daughter’s computer had file structure problems which didn’t allow some of the programs I usually use(Anti-Malware, SuperAntiSpyware) to work; the computer would lock up partway through. Spybot Search & Destroy did run all the way through without locking up the computer, but the virus was still there under my daughter’s login. I then did a system restore to a date a week earlier, and ran Spybot again, and this time it seems to have removed the virus. The computer is usable again, but I still have to figure out what’s wrong with the files that caused the programs to keep freezing up in certain folders.

Whatever program you use, use a different computer and download it to a flash drive and also download updates to the virus definitions, then install and run it. SuperAntispyware has a version that runs right off the flash drive and you don’t need to install it.

The computer was running Firefox browser with Adblock Plus. I’ve since added on the NoScript add-on. I don’t know if it would have prevented the virus or not.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [June 1, 2011, 8:32am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/4 "2011-06-01T08:32:16Z")

</div>

I wouldn’t trust antispyware to get rid of a rootkit. Use an offline scanner, like the [Avira Rescue CD](http://www.avira.com/en/support-download-avira-antivir-rescue-system).

Rootkits are serious business. This is how I removed it from my uncle’s computer. Unlike when I contracted Vundo (from a suspicious download), I did not wind up having to reformat the computer because I kept getting reinfected.

After you run the CD, do at least a repair installation.

---

<div class="post-metadata">

**Author:** ![monstro](https://avatars.discourse-cdn.com/v4/letter/m/ba9def/32.png) [@monstro](https://boards.straightdope.com/u/monstro)\
**Post date:** [June 1, 2011, 10:52am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/5 "2011-06-01T10:52:53Z")

</div>

I had it last week. I took it to the repairman and after working on it all day, he said it had been quite a difficult one to remove but he did it (and for cheap, too!). I had virus protection software but it somehow missed it. The guy put some other programs on there to serve as back-up.

If you’ve got some money to spare, I say go and find a nice local repair person to fix it.

---

<div class="post-metadata">

**Author:** ![needscoffee](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/needscoffee/32/1076_2.png) [@needscoffee](https://boards.straightdope.com/u/needscoffee)\
**Post date:** [June 1, 2011, 7:34pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/6 "2011-06-01T19:34:32Z")

</div>

Here’s a newsletter from today on it. [Virus Alert - XP Total Security 2011](http://askbobrankin.com/virus_alert_xp_total_security_2011.html?awt_l=OV4Wp&awt_m=J.r1p0Fis8P6SL)  
Antimalwarebytes is recommended as being able to remove it. I forgot to mention the tip about renaming it from a .exe to a .com file if it won’t run for you.

I did run several rootkit cleaner programs on my infected computer, and none of them detected anything.

---

<div class="post-metadata">

**Author:** ![Baron\_Greenback](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/baron_greenback/32/48_2.png) [@Baron\_Greenback](https://boards.straightdope.com/u/Baron_Greenback)\
**Post date:** [June 1, 2011, 7:59pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/7 "2011-06-01T19:59:21Z")

</div>

> [@needscoffee](#):
>
> Here’s a newsletter from today on it. [Virus Alert - XP Total Security 2011](http://askbobrankin.com/virus_alert_xp_total_security_2011.html?awt_l=OV4Wp&awt_m=J.r1p0Fis8P6SL)  
> Antimalwarebytes is recommended as being able to remove it. I forgot to mention the tip about renaming it from a .exe to a .com file if it won’t run for you.

I’ve seen a few variants of this recently, and renaming mbam.exe to [mbam.com](http://mbam.com) hasn’t worked in every case. I had some success with infected family and friends machines with renaming to mbam.scr, and in one case iexplore.exe.

---

<div class="post-metadata">

**Author:** ![Valgard](https://avatars.discourse-cdn.com/v4/letter/v/7feea3/32.png) [@Valgard](https://boards.straightdope.com/u/Valgard)\
**Post date:** [June 1, 2011, 8:50pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/8 "2011-06-01T20:50:01Z")

</div>

My g/f’s notebook just got hit with this last week. It got by AVG antivirus and MS Windows Defender which were up to date.

It’s a real pain in the butt to deal with. I wound up doing a system restore to the previous day which got rid of it and made the machine functional again, although it does try and “hide” the system restore utility from you. Deleted the dodgy executables and registry entries that it left behind. Installed Malwarebytes and ran a complete scan, it found nothing at that point.

However it did go through and delete all of her photos, music, Office docs and ZIP files. I used Pandora file recovery to undelete everything (both Pandora and Malwarebytes are free downloads from CNET).

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 1, 2011, 10:38pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/9 "2011-06-01T22:38:07Z")

</div>

> [@Valgard](#):
>
> However it did go through and delete all of her photos, music, Office docs and ZIP files.

Well, it didn’t really delete them, it flipped the hidden file bit so you couldn’t see them. There is a tool called unhide.exe in my cite that will undo that.

---

<div class="post-metadata">

**Author:** ![Valgard](https://avatars.discourse-cdn.com/v4/letter/v/7feea3/32.png) [@Valgard](https://boards.straightdope.com/u/Valgard)\
**Post date:** [June 1, 2011, 10:54pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/10 "2011-06-01T22:54:51Z")

</div>

> [@Fear\_Itself](#):
>
> Well, it didn’t really delete them, it flipped the hidden file bit so you couldn’t see them. There is a tool called unhide.exe in my cite that will undo that.

Ah! Good to know, thanks! I’ll run unhide.exe on her machine next time.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [June 1, 2011, 11:00pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/11 "2011-06-01T23:00:46Z")

</div>

Malwarebytes is pretty consistently killing these virii as they come up.

As mentioned before it hides the files not deletes, its all part of the “scareware” methodology thye use to try and coax a user to cough up a Credit card #.

even without the unhide utility you can right click on your docs and settings or users folder, select properties, and uncheck “hidden” then select “apply to all folders subfolders and files.” may take a few min, but they come back.

If malwarebytes is having a hard time running, rename mbam.exe to iexplore.exe and run it. They allow files named iexplore to run to enable users to hand over CC#'s via a web interface.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [June 1, 2011, 11:02pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/12 "2011-06-01T23:02:17Z")

</div>

Also there is a new version of malwarebytes as of yesterday afternoon. 1.51 comes with a trial of the pro version, we are testing it out this week in the shop.

---

<div class="post-metadata">

**Author:** ![gaffa](https://avatars.discourse-cdn.com/v4/letter/g/e68b1a/32.png) [@gaffa](https://boards.straightdope.com/u/gaffa)\
**Post date:** [June 1, 2011, 11:02pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/13 "2011-06-01T23:02:54Z")

</div>

Yeah, I ran into two different machines with this in the last week. A real pisser, but I was able to get all their files back and their machines clean.

Never, ever browse social networking sites using an account with Administrator privileges. Always create a Standard or Limited account to do so. And if you run a moronic piece of software like Peachtree that doesn’t allow it - DUMP that shit and join us in the 21st century.

---

<div class="post-metadata">

**Author:** ![Hippy\_Hollow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hippy_hollow/32/4841_2.png) [@Hippy\_Hollow](https://boards.straightdope.com/u/Hippy_Hollow)\
**Post date:** [June 2, 2011, 3:20am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/14 "2011-06-02T03:20:02Z")

</div>

I was called in to triage for my family’s PCs (running XP)… Once I had some time to sit down and Google, got rid of it pretty easy. You Ctrl-alt-del to get the Task Manager to appear, kill the recovery program, then click on the processes tab and kill the one with the garbled name that ends in .exe.

Google for “unhide.exe” from [BleepingComputer.com](http://BleepingComputer.com) for a program that will bring most of your shortcuts, etc. back.

I really hate dealing with Windows and malware. As a Mac user, I never even give this stuff a moment’s thought…

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 2, 2011, 8:07am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/15 "2011-06-02T08:07:32Z")

</div>

> [@Hippy\_Hollow](#):
>
> I really hate dealing with Windows and malware. As a Mac user, I never even give this stuff a moment’s thought…

Perhaps you should:

[Apple Updates Mac OS X To Battle Malware Threats](http://news.yahoo.com/s/nf/20110601/bs_nf/78778)

The MacGuard malware has [already adapted to the update](http://www.bleepingcomputer.com/forums/topic401082.html):

> [@](#):
>
> To bypass this new update, the Mac rogue developers have already released a new version of the Mac Guard downloader. Instead of using the old installer called **avSetup.pkg** and the downloader app called avRunner, it instead installs a different installer called **mdInstall.pkg** and a download application named **mdDownloader**. This new version of the downloader is not detected by Security Update 2011-03 and allows the program to be easily installed.
> 
> My advice to Mac owners is to get an anti-virus software installed. These rogue programs are not going away and will only get worse.

---

<div class="post-metadata">

**Author:** ![needscoffee](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/needscoffee/32/1076_2.png) [@needscoffee](https://boards.straightdope.com/u/needscoffee)\
**Post date:** [June 4, 2011, 11:09pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/16 "2011-06-04T23:09:47Z")

</div>

I forgot to mention that my daughter forgot to mention that all her documents and media files had been turned invisible, but thanks to **Fear Itself** we knew what had happened and how to fix it. Thanks!

---

<div class="post-metadata">

**Author:** ![Darth\_Panda](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@Darth\_Panda](https://boards.straightdope.com/u/Darth_Panda)\
**Post date:** [June 4, 2011, 11:31pm UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/17 "2011-06-04T23:31:02Z")

</div>

I had it about a week and a half ago - went into safe mode and ran avira but didn’t get great results, although I was able to use it to restore task manager functionality. Rebooted into regular mode, killed the processes with task manager which let boot sequence continue, then ran rkill followed by malwarebytes followed by unhide. Pain in the arse, but no real damage done.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [June 5, 2011, 12:32am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/18 "2011-06-05T00:32:34Z")

</div>

Note that my advice isn’t to not run malwarebytes, but to run an offline virus scan afterwards to be sure you are clean, and don’t have anything else hanging around. I really wish malwarebytes would come up with an offline scanner so we wouldn’t have to deal with the renaming thing.

---

<div class="post-metadata">

**Author:** ![needscoffee](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/needscoffee/32/1076_2.png) [@needscoffee](https://boards.straightdope.com/u/needscoffee)\
**Post date:** [June 5, 2011, 12:34am UTC](https://boards.straightdope.com/t/windows-vista-recovery-virus/583921/19 "2011-06-05T00:34:01Z")

</div>

> [@BigT](#):
>
> Note that my advice isn’t to not run malwarebytes, but to run an offline virus scan afterwards to be sure you are clean, and don’t have anything else hanging around. I really wish malwarebytes would come up with an offline scanner so we wouldn’t have to deal with the renaming thing.

SuperAntiSpyware has a portable version, but I don’t know if it removes this or not.
