Description of Windows 7 Recovery and consequences of its residing on your PC

Unscrupulous developers of Windows 7 Recovery intentionally provided for no facility for solving existing and emerging security issues related to computer security.
According to the developer’s description of the program under review, it is an ultimate system protection utility. Consequentially, the program is but another misleading security tool that provides fake security services. Its actual objectives consist of blackmailing users and enabling remote attacker to watch processes of computer system infected with the advertising parasite.  The blackmailing is a determination for activities of the misleading program related to security of computer system. Detecting not a single real virus the adware nevertheless points out dozens of cases to be resolved instantly or else computer system is badly damaged or totally destroyed. That is the very essence of the blackmailing to ask for a paid activation in order to resolve the critical cases.
Apart from the blackmailing, the malware spies on infected computer system and, if possible, informs remote hackers of the recent history of events on a PC under unauthorized observation.  It is a guesswork what kind of use the info recipients are about to get from that.
Windows 7 Recovery Technical Details:

  • Full name: Windows 7 Recovery, Windows7 Recovery, Win 7 Recovery, Win7 Recovery
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian Federation

Signs of being infected with Windows 7 Recovery

There are few cases of detection problems, most of which relate to the situation of a partial, i.e. incomplete installation of the program. Because of the incomplete installation, the adware popups show is not complete. The detection may be complicated, if no entries of the adware names occur in the popups so that users are not informed of the source of alerts they see.
That may be very dangerous for users and advantageous for the swindlers spreading the adware as credulous users treat the anonymous security alerts as genuine system (Windows) messages. This increases in times a peril of user’s haste decision to waste money into the adware instead of removing Windows 7 Recovery.
Windows 7 Recovery automatical removal:

Apart from advertising viruses of extended payload like the one in question, your PC is likely to be occupied by a range of other threats of rather destructive tasks set for them by their developers. The probability of that is doubles due to the fake protection that exposed your PC to adverse environment more intensively than system without any protection, other things being equal.
Manual Removal of Windows 7 Recovery:

Please take into account that, subject to the way of the adware introduction, its deletion may need to cover related infections, which vary from case to case.
If you have not installed the program, it is strongly advised that you scan your computer system and exterminate the adware illegal installer before removing it applying one of the two extermination techniques provided in this article.

Remove Windows 7 Recovery files and dll’s:

%UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery
%UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery\Uninstall Windows 7 Recovery.lnk
%UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery\Windows 7 Recovery.lnk
%UserProfile%\Desktop\Windows 7 Recovery.lnk

Unregister Windows 7 Recovery registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′

