Wednesday, March 23, 2011

Remove Windows Recovery – Uninstall WindowsRecovery Virus

Another fake antispyware program has been detected in a number of propagation schemes, both newly detected and already known to IT security experts.
Signals on the monitor and sound signals are used by this program to convince users of the need to cooperate with it. The cooperation, in the meaning of Windows Recovery (WindowsRecovery), is that extended rights are granted to this program. However, it would obtain them in another tricky way sooner or later, unless you get rid of Windows Recovery in a good time.
The adware also wants your money to be paid for its activation. Warning! Do not buy the counterfeit  for the adware may be dropped in a kit with keylogger. Thus your financial privacy may be compromised. If already bought the adware, please contact your bank or another authority providing financial services to you. Removal of Windows Recovery and detection and extermination of other threats is available here.

Windows Recovery screenshot:


Windows Recovery removal tool:


Windows Recovery manual removal guide:
Delete Windows Recovery files:
%TempDir%[random.exe]
Delete Windows Recovery registry entries:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “[random].exe”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “[random]”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments “SaveZoneInformation” = ‘1′
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “WarnonBadCertRecving” = ‘0′
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem “DisableTaskMgr” = ‘1′

1 comment:

Anonymous said...

hello and thanks followed instructions and all is well


Bruce Smith