Three programs for successful removal of System Recovery virus
System Recovery malware (also referred to as SystemRecovery) is the virus which has been the subject of several our posts recently. Its successful removal is a feasible task for GridinSoft Trojan Killer. However, running GridinSoft Trojan Killer is not enough in this case, even though the program recommended by us indeed deletes all malicious files and registry entries of the above-mentioned scam. The point is that even after successful elimination of SystemRecovery fake defragmenter the problems caused by it still remain. These problems include missing icons, disappeared desktop, missing files and folders as well as all the programs in the Start menu. Two additional programs developed by GridinSoft LLC can restore your system back to normal (previous) condition, the state in which your PC was before the virus infiltration. These applications are GridinSoft Unhider and GridinSoft Restore. Below please find the information about where to download them and how to use them free of charge.
GridinSoft Unhider download link:
GridinSoft Restore download link:
Finally, please watch the excellent video presentation showing how exactly to get rid of System Recovery virus using GridinSoft Trojan Killer and how to revive your system using these two additional applications recommended by us (which are free, by the way). Please make sure to contact us at any time if you need our assistance on any further issues.
System Recovery automatic removal:
Download the latest version of GridinSoft Trojan Killer, install and run it.
System Recovery manual removal:
Delete System Recovery files:
%StartMenu%\Programs\System Recovery\System Recovery.lnk
%StartMenu%\Programs\System Recovery\Uninstall System Recovery.lnk
Delete System Recovery registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" =
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'