Severity scale:  
  (72/100)

Data Recovery. How to remove? (Uninstall guide)

removal by Jake Doevan - -   Also known as DataRecovery | Type: Rogue Antispyware

At the end of April 2012 new virus appeared with the same Data Recovery name. Its i a different program, please take a look at the screenshots to see with which Data Recovery you are infected with. The new Data Recovery virus we named Smart Data Recovery as this virus changed Smart HDD virus and share the same GUI.

Data Recovery is a rogue computer optimization program that displays fake critical security errors and reports registry, hard drive problems that do not even exist. It's not the first of its kind but this fake application may seriously compromise your privacy and restrict access to various application and files. It's a clone and System Recovery scam. Data Recovery runs a fake system scan and states that your computer has hard drive and RAM problems. It displays fake alerts claming that you can lose your important data anfd files if you won't fix the supposed problems immediately. That's a typical scam used to scare users into thinking that their computers are infected and to “push” bogus software to fix the problems. Data Recovery is distributed via hacked websites and fake virus scanners. If you manged to infect your PC with this fake computer optimization program you'll notice that right away. The rogue program will hide shortcuts and make your Dekstop black. It will also hide other files on your computer to make you think that there are some serious hard drive failures. You will have to unhide those files manually. Also, do not delete files from Windows temp folder. Data Recovery copies certain files to %Temp%\smtmp folder and if you remove those files, you've have to run Windows recovery disk because there is no other way to restore system shortcuts and files. We recommend STOPzilla. Some of the messages that will randomly be displayed are:

Data Recovery DiagnosticsWindows detected a hard disk error.
A problem with the hard drive sectors has been detected. It is recommended to download the
following sertifiedsoftware to fix the detected hard drive problems. Do you want to download recommended software?

Requested registry access is not allowed.
Registry defragmentation required
Hard Drive rotational speed decreased by 20%
Disk drive C:\ is unreadable.
System files are damaged.System is unstable.
The problem may cause errors while loading operating system
Ram memory speed decreased significantly and may cause system failure.

Critical Error!
Damaged hard drive clusters detected. Private data is at risk.

Critical Error

Hard Drive not found. Missing hard drive.

Please note that you may have to follow the removal instructions in safe mode with networking because most of the programs need to remove Data Recovery is are blocked in normal mode. Last, but not least, do not purchase this fake program. It's a scam. If you have already paid for it, contact your bank and dispute the charges. Then use STOPzilla to remove Data Recovery from your computer. Just enter the activation code given above, install Reimage, Malwarebytes MalwarebytesCombo Cleaner or Plumbytes Anti-MalwareMalwarebytes Malwarebytes and run a full system scan. It will remove the rogue program and related viruses from the system.

These activation codes that could help you to disable this virus are: 1203978628012489708290478989147 or 08869246386344953972969146034087.

The latest parasite names used by FakeHDD:
[newest id=”fakehdd”]

Offer
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Malwarebytes.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.
Data Recovery snapshot
Data Recovery

Data Recovery manual removal:

Kill processes:
[random].exe

6DSS92c31Apgjk.exe

Delete registry values:
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Use FormSuggest" = 'Yes'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "CertificateRevocation" = '0'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnonBadCertRecving" = '0'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop "NoChangingWallPaper" = '1'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments "SaveZoneInformation" = '1'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer "NoDesktop" = '1'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = '1'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[random].exe"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[random]"

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "DisableTaskMgr" = '1'

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "CheckExeSignatures" = 'no'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced "Hidden" = '0'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced "ShowSuperHidden" = '0'

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerComDlg32LastVisitedMRU "MRUList"

Delete files:
[random].exe

6DSS92c31Apgjk.exe

About the author

Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions

Removal guides in other languages