logo

Sunday 20th of May 2012

Resources


Home Latest Spyware threats Windows Recovery Removal Instructions
Windows Recovery Removal Instructions PDF Print E-mail
Wednesday, 04 May 2011 20:14
It is not a top secret that Windows Recovery (WindowsRecovery) is not a genuine system utility but a pretended computer antivirus. Moreover, it is rather a matter of common knowledge so that most of the victims of the counterfeit would not install this program, if they could have known its name before the installation.
In the other words, the fake antivirus tends to keep its name undisclosed in the course of  its installation. Further on, in many instances the secret of its name is kept for a long while after its installation.
The purpose of the trick is on the surface. The name is concealed to reduce the risk of Windows Recovery removal. Even if the adware name is eventually disclosed and user attempts to get rid of Windows Recovery adware, the attempts would fail unless proper fix or method is used. Click here to get a fix for Windows Recovery issue, which is available in a free scanner mode.

 

 

 

Automated tool to remove Windows Recovery:

Having the malware onboard puts your computer system safety and stability at risk. Even if the above sections of this review state that infection is unlikely to slow the computer down or do other damage, the programs it may come bundled with are very likely to do that. In this connection, be aware that the reviewed parasite is often bundled with so called subservient malware like virus or worm.
That is to say how important is at least to start removing Windows Recovery automatically, for that would launch free malware scan and thus aware you about all the infections actually threatening your computer system.
In order to start free scan as a first step to the final goal of Windows Recovery removal and other infections disposal, click here.


How to get rid of Windows Recovery manually?

Please, follow the instructions below precisely in order to kill the cyber threat manually paying attention that you need to print out this removal guide, because text editors and any other software shall not be applied during the threat extermination. The best way to ensure compliance with the above requirement is to reboot and disconnect to the Internet before removing Windows Recovery.


Remove
Windows Recovery files:

%AllUsersProfile%\Application Data\~<random>
%AllUsersProfile%\Application Data\~<random>r
%AllUsersProfile%\Application Data\<random>.dll
%AllUsersProfile%\Application Data\<random>.exe
%AllUsersProfile%\Application Data\<random>
%AllUsersProfile%\Application Data\<random>.exe
%UserProfile%\Desktop\Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\
%UserProfile%\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk

Remove Windows Recovery registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "<random>.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "<random>"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = 0'
 

Who's Online

We have 5 guests online


Powered by Joomla!. Designed by: Free Joomla Theme, web ftp. Valid XHTML and CSS.