Saturday, June 11, 2011

How to remove Windows Vista Restore virus and sake system utility

Windows Vista Restore is a false accuser. According to its words, system and program files, some of which might be of critical importance for computer system, are subject to immediate extermination as they are marked with names of popular errors and threats and said to cause damage to computer system.
Reality is just the opposite as the files blamed by the counterfeited security and system tool do not pose any challenge to computer security, but their deletion do.  Cases have been reported of deletion of groundlessly accused by the malware files that resulted into system collapse.
Get rid of Windows Vista Restore fake system tool and detect and exterminate real errors and viruses following this link.

Windows Vista Restore virus snapshot:



Windows Vista Restore remover download:


Manual removal guide:
Delete infected files and related folders:

%AllUsersProfile%\Application Data\~r
%AllUsersProfile%\Application Data\[random].dll
%AllUsersProfile%\Application Data\[random].exe
%AllUsersProfile%\Application Data\[random]
%AllUsersProfile%\Application Data\[random].exe
%UserProfile%\Desktop\Windows Vista Restore.lnk
%UserProfile%\Start Menu\Programs\Windows Vista Restore\
%UserProfile%\Start Menu\Programs\Windows Vista Restore\Uninstall Windows Vista Restore.lnk
%UserProfile%\Start Menu\Programs\Windows Vista Restore\Windows Vista Restore.lnk

Delete Windows Vista Restore virus registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'

No comments: