mrtipso Admin
Posts : 171 Reputation : 9 Join date : 2011-07-05 Age : 36 Location : Pasir Gudang, Johor
| Subject: How to Remove "System Restore" Virus Sat Oct 22, 2011 3:34 pm | |
| System Restore virus will pretend as one program that focuses on hard drive and system optimization. However, in reality, this is another addition to the lists of fake hard drive defragmentation program. It differs from other rogue programs that will produce virus scan on the system. What System Restore virus does was scan the PC for known system and hard drive errors. This fake application will provide PC Performance & Stability Analysis Report that will show false information regarding initialization errors, bad sectors and a bunch of critical errors. It also displays a bunch of fake pop-up alerts informing users of hard drive and system malfunction. Issuing these types of alert is specifically to make users think that computer needs a licensed version of System Restore to be able to resolve given errors. Malware authors push their programs to the edge where it can even disable legitimate antivirus programs on target machine. Therefore, System Restore reigns as the sole security and optimization software at hand. The real solution to this kind of problem is to remove the culprit itself. Removing System Restore virus from a compromised system will also stop excessive annoyances it brings. Only use a legitimate anti-virus application and we discourage you to purchase the fake and unknown software. Screen Shot Image: Update: October 10, 2011New version of System Restore has this new Graphical User Interface. The new skin is also use in several other variants from the same rogue family. Technical Details and Additional Information:Damage Level: MediumSystems Affected: Windows 9x, 2000, XP, Vista, Windows 7 - Spoiler:
Characteristics (Analysis)This rogue security application drops the main executable file under this folder: c:\documents and settings\all users\application data\6dss92c31apgjk.exeMalware Behavior “System Restore” virus provides extreme annoyances on the computer once installed. It may redirect Internet browser to several malicious pages. The malware also displays pop-up and system tray alerts typically promoting the rogue application. - Quote :
- System Restore Diagnostics
Windows detected a hard disk error. A problem with the hard drive sectors has been detected. It is recommended to download the following certified software to fix the detected hard drive problems. Do you want to download recommended software?
Hard Drive Failure The system has detected a problem with one or more installed IDE / SATA hard disks. It is recommended that you restart the system.
System Error An error occurred while reading system files. Run a system diagnostic utility to check your hard disk drive for errors. Added Registry Entries: - Quote :
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run "(random characters).exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "(random characters)" HKCU\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes' HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0' HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0' HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1' HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;' HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1' HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1' HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1' HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1' HKCU\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no' HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0' HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0' Associated Files and Folders: - Quote :
- %LocalAppData%\(random characters)
%LocalAppData%\(random characters).exe %LocalAppData%\~(random characters) %LocalAppData%\~(random characters) %StartMenu%\Programs\System Restore\ %StartMenu%\Programs\System Restore\System Restore.lnk %StartMenu%\Programs\System Restore\Uninstall System Restore.lnk %Temp%\smtmp\ %UserProfile%\Desktop\System Restore.lnk Video Tutorial[You must be registered and logged in to see this link.]or here [You must be registered and logged in to see this link.] | |
|
dont karnain Moderator
Posts : 27 Reputation : 7 Join date : 2011-09-23 Age : 33 Location : Kuala Nrang..Kedah
| Subject: Re: How to Remove "System Restore" Virus Tue Jan 24, 2012 4:53 pm | |
| terbaik software..........berguna ...softwrae yg mnarik | |
|