Description of Windows XP Recovery and consequences of its residing on your PC

Windows XP Recovery is member of a growing group of counterfeits going back through Windows Restore, Windows 7 Recovery, WinHDD and others up to SystemDefragmenter, the initial fake system defragmenter.
The program in question is normally installed on XP systems, exceptions are consequences of misidentification of a computer system.
The program is installed by general installer, which is installed on any Windows system to identify its version and  orders appropriate program download and installation. By introduction method the installer is classified as a trojan or a worm or a virus so that a number or routines is applied to propagate it.
Once installation of the adware is complete, the installer tries to further propagate in a wormlike fashion. It is considered to be an integral part of the adware, yet it has a potential for worming its way from PC to PC through networks and removable memory.
Windows XP Recovery Technical Details:

  • Full name: Windows XP Recovery, WindowsXP Recovery, Windows XPRecovery
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian Federation

Signs of being infected with Windows XP Recovery

It is possible to get rid of Windows XP Recovery “in advance”, if you have just noticed a popup notifying of the need to install it due to certain system issue – for instance, hard drive memory damage. That is, the threat consists of the installer, which suggests the program installation to fix certain problem, and the fake system improvement tool as such.
The installer has its own facility for producing popups, which is active until the main part of the adware is installed.
If you have been invited to install Windows XP Recovery, it is a sign of its installer in your computer memory.
Further signs of the adware are too easy to detect to describe them. Plenty of popups of betray the fake system utility presence.
Windows XP Recovery automatical removal:

Windows XP Recovery is evaluated as an average severity threat. However, its removal is critical for proper system functioning.
Manual Removal of Windows XP Recovery:

Manual routine of Windows XP Recovery removal covers the installer involved as an essential adware component. It is important to delete every entry specified below to avoid the adware regeneration.

Remove Windows XP Recovery files and dll’s:

%AllUsersProfile%\Application Data\~<random>
%AllUsersProfile%\Application Data\~<random>r
%AllUsersProfile%\Application Data\<random>.dll
%AllUsersProfile%\Application Data\<random>.exe
%AllUsersProfile%\Application Data\<random>
%AllUsersProfile%\Application Data\<random>.exe
%UserProfile%\Desktop\Windows XP Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows XP Recovery
%UserProfile%\Start Menu\Programs\Windows XP Recovery\Uninstall Windows XP Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows XP Recovery\Windows XP Recovery.lnk

Unregister Windows XP Recovery registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′

Windows XP Recovery