Description of System Recovery and consequences of its residing on your PC’s

Technical Details and screenshots:

  • Full name: System Recovery, System-Recovery
  • Type: Rogue anti-spyware
  • Origin: Russian Federation, Belarus

Signs of being infected with System Recovery

The following order is typically set for the adware popups, which could be reasonably defined as its visual symptoms that require no special skill to be observed by user.
If you install the adware, or let trojan or malicious scripts of corrupted page fulfill this task, it gains permit to run automatically as system process spawns sub-process which turns out to be the adware’s executable running.
This enables several messages to popup. Those messages assess specific aspects of system performance such as RAM or System Registry or data safety. For example, such alert may run as follows:

“Data Safety Problem. System integrity is at risk.”

The user is forced to click on those alerts as they will not be gone by their own and need to be clicked on or require another response. This activates process responsible for the main GUI appearance, which consists of several categories and directly demands from user activation of “full-functional version”.
System Recovery automatical removal:

To remove System Registry is inevitable and essential step of purging memory of your PC – of course, if your PC got infected with the aforementioned counterfeit. Without prejudice to completeness of the adware extermination, the tool above will ensure exposure and deletion of every malicious resident of your PC.

Manual Removal of System Recovery:

To manually delete the annoying fraudware, you might need to tame its processes first. If the adware entries are reported unavailable for deletion, try ending relevant process in Task Manager or prevent them from running by changing system configuration in Boot Menu to Safe Mode.

Remove System Recovery files and dll’s:


Unregister System Recovery registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[SET OF RANDOM CHARACTERS].exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[SET OF RANDOM CHARACTERS]”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’

