Saturday, April 28, 2012

Remove Data Recovery virus popups that fake system optimization

Data Recovery (DataRecovery)  is advertised as a  utility for  dealing with such aspects  of computer system as  hard drive reading errors,  junk files, excessive system registry values.  Unlike fake antispyware  programs, the  infection of this kind does not pretend to  deal with viruses.  It is focused on system and software errors  occurring due to incorrect system  settings and use.
To justify its  alert the adware does not hesitate  producing errors  on its own. It  makes  a range of applications fail  when they are running so  as to make user  convinced the reported problem discovered by the program is for real.
Introduction method for the counterfeit is based on drive-by downloads. Even  manual installation is unfair, for users is misinformed in relation to the program features.
Removal of Data Recovery  counterfeit  is blocked and complicated  by the parasite, nothing to say of the  compliance to system rules  for  installing/uninstalling  software.
Get rid of Data Recovery  as another  annoying parasite  that terrorizes its users with  silly  popups and denial of services attacks.  Free scanner available here is a tool for cleaning counterfeits of various kind and real infections. It is a validated method for the above malware extermination.

Data Recovery license code (helps removal):
 NOTE: "Activating" Data Recovery is not enough. You need to remove related trojans \ rootkits using reliable malware removal solution.
It is important to fix Windows registry after Data Recovery malware removal using safe registry cleaner software.

Data Recovery screenshot:

Data Recovery manual removal guide:
Delete infected files:
%AppData%\Microsoft\Internet Explorer\Quick Launch\Data Recovery.lnk
%Desktop%\Data Recovery.lnk
%StartMenu%\Programs\Data Recovery\
%StartMenu%\Programs\Data Recovery\Data Recovery.lnk
%StartMenu%\Programs\System Check\Uninstall Data Recovery.lnk
Delete infected registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘Yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoDesktop” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “{random}.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “{random}”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = ’0′

No comments: