Home Malware Programs Rogue Anti-Virus Programs MS Recovery Tool

MS Recovery Tool

Posted: April 10, 2011

Although its name attempts to present MS Recovery Tool as a legitimate Microsoft-based application, MS Recovery Tool is a rogue anti-malware program heavily-based on previous PC threats. MS Recovery Tool uses false positives in its system alerts and infection warnings to cause the user to assume that the computer is in danger, and then requests a registration key purchase to remove these problems. Rogue programs in the MS Recovery Tool family are also known to cause the abrupt termination of various applications, particularly applications capable of detecting or removing MS Recovery Tool. Deleting MS Recovery Tool by using sufficiently strong anti-malware software is strongly encouraged due to the inherent security vulnerabilities caused by the latter behavior.

What MS Recovery Tool Wants from You

MS Recovery Tool is a known relative of older rogue security programs from the family like MS Recovery Tool has nothing to do with Microsoft, but banks on you trusting the name. Infection by MS Recovery Tool can be caused by downloading files from suspicious sources like P2P networks and unfamiliar websites; always remember to download Microsoft applications from official sources.

MS Recovery Tool will begin its attacks on your PC by tossing a few lines in your Registry to let MS Recovery Tool launch whenever Windows itself is launched. Thereafter, MS Recovery Tool will start displaying scans that show multitudes of infections, along with messages like these:

MS Recovery Tool
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss.

MS Recovery Tool Warning
Intercepting programs that may compromise your private and harm your system have been detected on your PC.

Click here to remove them immediately with MS Recovery Tool.

Warning: Your computer is infected
Windows has detected spyware infection!
Click this message to install the last update of Windows security software...

MS Recovery Tool
Your PC is infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details.
Click here to activate protection.

Security Monitor: WARNING!
Attention: System detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. Your private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need to update your current security software.
CLick [sic] Yes to download official intrusion detection system (IDS software).

MS Recovery Tool will tell you that removing these threats requires a registration process, but this is just a way to scam you out of money. All detection results by MS Recovery Tool are completely fake.

The Second Harmful Use MS Recovery Tool Puts Its Errors Towards

MS Recovery Tool may also use error messages when it shuts down an application, which can occur frequently and without your consent. This standard rogue program trick is MS Recovery Tool's primary defense mechanism against deletion, since you can't delete MS Recovery Tool properly if you can't run your anti-malware software!

If you want to remove MS Recovery Tool, the first thing you need to do is establish an environment that MS Recovery Tool can't unduly influence. The easiest way to do this is to reboot your PC into Safe Mode, which is available on all Windows operating systems. In most cases, Safe Mode will stop less advanced rogue programs like MS Recovery Tool from launching automatically, which then lets you run any application you please.

Although you may try to remove MS Recovery Tool by deleting its files and Registry entries yourself, this is a method that's prone to error and undesirable side effects. The recommended alternative is to use anti-malware software to scan for and delete MS Recovery Tool along with anything related to it. Update your scanners before running them and MS Recovery Tool should pose no further trouble for you or your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\
    2 c:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS]
    3 c:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[RANDOM CHARACTERS]"

Additional Information on MS Recovery Tool

  • The following messages's were detected:
    # Message
    1 MS Removal Tool Warning
    Your PC is infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details.
    Click here to activate protection.
    2 MS Removal Tool Warning
    Intercepting programs that may compromise your privacy and harm your system have been detected on your PC.
    Click here to remove them immediately with MS Removal Tool.
Loading...