Disk Recovery can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Disk Recovery. Finally, all the file related to Disk Recovery must be deleted from the hard drive. All of them has been shown in the removal guide below.
Disk Recovery should be removed immediately!
Disk Recovery Removal Guide
Kill Process
(How to kill a process effectively?)
[RANDOM].exe
Unregister DLL files
%Temp%\[RANDOM].dll
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"
Unregister DLL
%AllUsersProfile%\ApplicationData\[random].dll
%AllUsersProfile%\[random].dll
Remove Folders and Files
%AllUsersProfile%\ApplicationData\[random].exe
%AllUsersProfile%\ApplicationData\[random].dll
%AllUsersProfile%\ApplicationData\~[random]
%AllUsersProfile%\[random]
%AllUsersProfile%\[random].exe
%AllUsersProfile%\[random].dll
%AllUsersProfile%\~[random]
Disk Recovery should be removed immediately!
Disk Recovery Removal Guide
Kill Process
(How to kill a process effectively?)
[RANDOM].exe
Unregister DLL files
%Temp%\[RANDOM].dll
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"
Unregister DLL
%AllUsersProfile%\ApplicationData\[random].dll
%AllUsersProfile%\[random].dll
Remove Folders and Files
%AllUsersProfile%\ApplicationData\[random].exe
%AllUsersProfile%\ApplicationData\[random].dll
%AllUsersProfile%\ApplicationData\~[random]
%AllUsersProfile%\[random]
%AllUsersProfile%\[random].exe
%AllUsersProfile%\[random].dll
%AllUsersProfile%\~[random]
No comments:
Post a Comment