Windows Recovery is another virus (a fake rogue software) which claims to be a powerful windows and system security tool. Windows Recovery tool is a clone of Windows Safemode virus and System Diagnostic virus. All these softwares (including Windows Recovery) are bogus and useless. Windows Recovery is a scamware thats wants you to pay for its full version to protect your system from damages caused by viruses and spywares, Remember, Windows Recovery virus has no ability to detect and remove viruses or fix windows problems but it is a virus itself and it is a dangerous threat for your pc.

Just like other rogue spywares, WindowsRecovery virus uses the fake alerts and warning messages to scare user. It displays bunch of fake critical errors telling you about hard disk error, problem with RAM, System restore problem and many other errors. Mostly Windows Recovery virus attacks with fake hard disk drive errors. It may warn you of no disk found, or low disk space, or damage hard drive or something else. for example:
Fix Disk
Windows Recovery Diagnostics will scan the system to identify performance problems.
Start or Cancel
Critical Error!
Damaged hard drive clusters detected. Private data is at risk.
Critical Error
Hard Drive not found. Missing hard drive.
Critical Error
RAM memory usage is critically high. RAM memory failure.
Critical Error
Windows can’t find hard disk space. Hard drive error
Remember! All these warning messages and alerts displayed by Windows Recovery virus are fake. This program is specially designed to extort your money by offering you to buy its fake system security and optimization products. You should ignore these warnings, avoid buying this program, avoid its installation and immediately remove it from your computer upon detection.
How to remove Windows Recovery virus manually:
To remove this virus manually, complete the following set of tasks. Do not forget to create a backup before getting started to the manual removal guide.
Stop Windows Recovery processes:
[random name].exe
Disable Windows Recovery DLL files:
[random name].dll
Delete Windows Recovery Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′
Delete Windows Recovery files:
%AllUsersProfile%\~[random]
%AllUsersProfile%\~[random]r
%AllUsersProfile%\[random].dll
%AllUsersProfile%\[random].exe
%AllUsersProfile%\[random]
%AllUsersProfile%\[random].exe
%UserProfile%\Desktop\Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\
%UserProfile%\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk
%UserProfile%\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk
Auto Removal
To remove this virus Automatically, We suggest following tools:
Super Anti Spyware (Download)
Malware Bytes Anti-Malware (Download)



