Showing posts with label Recovery. Show all posts
Showing posts with label Recovery. Show all posts

Tuesday, October 4, 2011

Data Recovery - How to remove Fake Antivirus









Rogue Data Recovery hides all files and folders, and brings all the shortcuts in a some folder.


So that would find anything on your computer to show hidden files and folders.
To do this, open My Computer. In the menu click Tools - Folder Options.






Click the tab View. Scroll to the "Show hidden files and folders", select this option and click OK.






Now you can see the files and folders that were hidden in a consequence of virus infection.


Now again run My Computer and type in the address bar website trojan-killer.net and press Enter.






On this site you will need to download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



Thursday, September 29, 2011

Rogue Fake AV Data Recovery - how to detect and remove








Step 1.
Kill the malicious process yiEXcwRdRpIp.exe


Step 2.
Delete the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\yiEXcwRdRpIp.exe


Step 3.
Delete next files on your system disk:


C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Recovery.lnk
C:\Documents and Settings\Admin\Desktop\Data Recovery.lnk
C:\Documents and Settings\Admin\Local Settings\Temp\2.tmp
C:\Documents and Settings\Admin\Local Settings\Temp\P5tM1QBI6DSS92.exe.tmp
C:\Documents and Settings\Admin\Start Menu\Programs\Data Recovery\Data Recovery.lnk
C:\Documents and Settings\Admin\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk
C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk
C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe
C:\Documents and Settings\All Users\Application Data\yiEXcwRdRpIp.exe