Home Malware Programs Misleading Programs HDD Restore

HDD Restore

Posted: December 17, 2010

HDD Restore is used by hackers as a rogue system optimizer. This fake program spreads via Trojan malware and poses a serious threat to computer safety. HDD Restore entices users to buy its full version after claiming the system is problematic, and marketing itself as the solution. HDD Restore is infact useless and is only an imitation of a security program and is not able to provide any actual computer security service. HDDRestore will try to look like it was a part of the operating system all along and may even mimic notifications on the Windows OS.Other symptoms may include browser redirections to corrupt sites advertising malicious software and even browser failure. Ignore all fake security alerts and delete HDD Restore immediately upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\dfrg
    2 %Temp%\dfrgr
    3 %UserProfile%\Desktop\HDD Recovery.lnk
    4 %UserProfile%\Start Menu\Programs\HDD Restore\
    5 %UserProfile%\Start Menu\Programs\HDD Restore\HDD Restore.lnk
    6 %UserProfile%\Start Menu\Programs\HDD Restore\Uninstall HDD Restore.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
Loading...