2011年10月15日星期六

Fake System Restore Virus, How to Manually Remove Fake System Restore?

System Restore is fake antivirus program that pretends to be useful computer restore application.
Fake System Restore infects a computer with help of Trojan infection. It gets automatically installed on the compromised computer without user’s knowledge. Fake System Restore usually runs in the background seriously damages the computer in secret. If you find an automatic system scan performed and a “PC Performance & Stability analysis report” presenting on the screen, unfortunately, your computer has been infected with this fake System Restore virus.
“PC Performance & Stability analysis report” is associated with the fake System Restore, used by the rogue virus to scare you. It tells you that numerous infections are detected and system errors found on your computer, which is deceptive.
At the same time you get the “PC Performance & Stability analysis report”, you will find your computer runs abnormally, without access to certain files and program. And the pop-up will keep annoying you so that you can hardly do anything on the computer. Fake System Restore does not show its true face until a purchase window comes up. It asks you to pay and download a full version of System Restore in order to fix the “detected problems”. It is big scam that you can’t trust. You are strongly recommended to remove the fake System Restore virus immediately to protect your computer.

How do you remove fake System Restore?
Case 1: This fake thing just made my computer black screen. I can’t find the icon for my antivirus program to run to delete the virus. Also the start menu programs are gone… John
Case 2: My malwarebytes was stopped to run. I can’t access the Internet to download a removal tool, even safe mode did not help. What can I do???!!! Jackson
Learnt from many infection cases, we know that antivirus program cannot help you remove fake System Restore virus. You may ask that why security tools doesn’t work or stop it from infecting computers? Fake System Restore virus is created to have been changed the code, which helps it shun and disable antivirus programs. That’s why you have removal tool available, but the fake System Restore still get through. Manual removal is the only way to get rid of the fake System Restore virus.

How to manually remove fake System Restore virus?

1: Locate and delete fake System Restore associated files:

%LocalAppData%\
%LocalAppData%\.exe
%LocalAppData%\~
%LocalAppData%\~
%StartMenu%\Programs\System Restore\
%StartMenu%\Programs\System Restore\System Restore.lnk
%StartMenu%\Programs\System Restore\Uninstall System Restore.lnk
%Temp%\smtmp\
%Temp%\smtmp\1
%Temp%\smtmp\1
%Temp%\smtmp\2
%Temp%\smtmp\3
%Temp%\smtmp\4
%UserProfile%\Desktop\System Restore.lnk

2: Detect and remove fake System Restore related registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'

Manual removal of fake System Restore refers to key parts of computer system, any error may lead to system crash. If you have not sufficient expertise in dealing with that, help from online PC expert can be the easiest way to get rid of fake System Restore virus without any risk.

没有评论:

发表评论