Thursday, September 29, 2011

Rogue Fake AV Data Recovery - how to detect and remove








Step 1.
Kill the malicious process yiEXcwRdRpIp.exe


Step 2.
Delete the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\yiEXcwRdRpIp.exe


Step 3.
Delete next files on your system disk:


C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Recovery.lnk
C:\Documents and Settings\Admin\Desktop\Data Recovery.lnk
C:\Documents and Settings\Admin\Local Settings\Temp\2.tmp
C:\Documents and Settings\Admin\Local Settings\Temp\P5tM1QBI6DSS92.exe.tmp
C:\Documents and Settings\Admin\Start Menu\Programs\Data Recovery\Data Recovery.lnk
C:\Documents and Settings\Admin\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk
C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk
C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe
C:\Documents and Settings\All Users\Application Data\yiEXcwRdRpIp.exe

No comments: