PDA

View Full Version : "Windows Vista Recovery" - as if


The SSK
20th May 2011, 20:26
Sorry if this has cropped up already, but this evil beast has just about closed us down.

We have Vista, and until recently had only one workspace (is that what it's called?) Opened a second one recently, mainly to have a seperate itunes account.

"Windows Vista Recovery":yuk::yuk::yuk: has hijacked the browser on the first workspace, as soon as it's opened there is nowhere to go, you can't close it and you can't open anything else. The other workspace is unaffected but all our important stuff is blocked on the first one.

A ggl search recommended Spyhunter to get rid of it so duly purchased and ran, but it's still there. I downloaded and ran the free version of Adaware which identified 790 'errors' and fixed 100 of them - to fix the rest you have to buy the package (the Adaware I used to have was free, no strings:confused:)

I see there are D-I-Y solutions to get rid of it but I don't think I have the skills. Any suggestions? Mrs SSK is getting *very* fretful missing out on The Archers podcasts.

mixture
20th May 2011, 21:06
Are you per chance talking about Windows Profiles (i.e. different login for each user).

If so, then it's pretty straightforward to "rescue" your files from the broken profile.

green granite
20th May 2011, 21:15
Try using Malwarebytes (it's free) as per this article: Remove Windows Vista Recovery (Uninstall Guide) (http://www.bleepingcomputer.com/virus-removal/remove-windows-vista-recovery)

The SSK
22nd May 2011, 16:11
Hmm, Malwarebytes seemed to get rid of the nasty popup but it got rid of more too.

"Catalyst Control Centre: Host application has ceased to function"

The other profile (the one I'm using now) seems to be OK.

Mr Optimistic
22nd May 2011, 17:49
CCC is for your amd/ati graphics card. Just download again if you need it (someone a gamer ?).

The SSK
31st May 2011, 10:27
The machine is now in the hands of my wife's company's IT experts. Their initial assessment is that the documents associated with that profile are gone forever, most importantly our photo library and email history, contacts etc.

What was that? Backup? Yes, I know ... :(

Bushfiva
31st May 2011, 10:44
Tell the IT experts to have another look. They should be aware this particular trojan "loses" files by setting the +H bit.

Also, run Housecall by Trend Micro (it's free and is an on-line scanning service). It's slow but good.