Windows Recovery

Windows Recovery is a harmful hard drive optimization program that will initiate a scan even without user’s intervention. When this happens, it is assumed that Windows Recovery virus has already penetrated a computer and was able to modify system settings that made it run automatically. Coming from the same group who developed Windows Safemode and System Diagnostic, it was expected that this variant will be as dangerous as the old ones. Aside from disabling anti-virus application, Windows Recovery virus also prevent any installed programs from executing. Computer will be rendered unusable. Repeatedly, the malicious application prompts to purchase the Windows Recovery registration key to be able to make the PC stable again.

Instead of obtaining and spending for this useless application, it is best to scan the computer with legitimate anti-malware program. If none is present, download a copy from legitimate web site. This effective Windows Recovery removal tool is available for free. Download, install, update and thoroughly scanning the computer can help remove Windows Recovery virus completely.

Most importantly, be able to recognized and identify fake from legitimate security programs. Fake are those who made to be sold and marketed in a deceiving manner as stated above. Real one’s offers a trial period and are useful for a period of time. If trial period lapses, it prompts users to voluntarily obtain the full version, otherwise it will not work same as before. While fake software akin to Windows Recovery will punished user with annoying pop-up alerts and acquisition of the licensed version is enforce.

Screen Shot Image:

Alias: WindowsRecovery

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Added Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Explorer\Advanced "ShowSuperHidden" = 0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/ fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\policies\system "DisableTaskMgr" = '1'
Associated Files and Folders:
%UserProfile%\Desktop\Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\
%UserProfile%\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk
%AllUsersProfile%\~[random]
%AllUsersProfile%\~[random]r
%AllUsersProfile%\[random].dll
%AllUsersProfile%\[random].exe
%AllUsersProfile%\[random]
%AllUsersProfile%\[random].exe
File Location for Windows Versions:
  • %AllUserProfile% for Vista/7 user is C:\ProgramData while for Windows XP/2000 this is C:\Documents and Settings\All Users\
  • %UserProfile% for Vista/7 user is C:\Users\<Current User> for Windows Vista/7, for Windows XP/2000 this is C:\Documents and Settings\<Current User>.

How to Remove Windows Recovery

Manual Removal Procedure

1. Press Ctrl+Alt+Del on keyboard to stop the process associated to "Windows Recovery". When Windows Task Manager opens, go to Processes tab. Find and end this process.
(random characters).exe

2. You need to update your installed antivirus software. Please connect to the Internet and download the most recent database. This is a one-click process from your AV program’s console.
3. Thoroughly scan the computer and remove any threats found by your antivirus program. If delete option is not available, your best next choice is to quarantine the infected file. There is also a need to manually locate and delete malicious files. Please see the file section for items that are relevant to Windows Recovery Virus.

4. Next, you need to remove registry entries created by Windows Recovery. Please refer to registry section to view entries related to the rogue program. [how to edit registry]
5. Exit registry editor when you are done.

6. Get rid of Windows Recovery start-up entry by going to Start > Run, type msconfig on the "Open" dialog box. It will launch a new window containing System Configuration Utility. Click on the Startup tab and uncheck the following item.
(random characters).exe

7. Click Apply. You need to restart Windows.

Windows Recovery Virus Removal Tool

For not so technical users that cannot comprehend with the manual removal. This automatic detection and cleaner is recommended. However, you need to download and install a tool to complete this process. The tool is free to download. We highly advise the use of this program to automatically delete all files and registry entries created by Windows Recovery. Remember that erasing system files required by the operating system may cause erratic behavior. It may also lead to system malfunction. Proceed with Windows Recovery automatic removal.

Use A Portable SuperAntiSpyware:
For complete removal of the virus, carry out a separate scan using different security program. This may catch infected items that evade your previous scan. Download and run SuperAntiSpyware Portable Scanner.