Click on screenshot to zoom
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Slow internet connection
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Data Repair

Data Repair is a direct clone of Master Utilities, PC Repair and Windows Repair. This rogue defragmenter was designed not to detect errors and offer solutions, but instead to act as a vehicle with which criminal developers rip honest consumers off. This rogue defragger improves on its predecessors’ attack, and enters the system surreptitiously without the user’s knowledge or consent.

Download Spyware Removal Tool to Remove* Data Repair
  • Quick & tested solution for Data Repair removal.
  • 100% Free Scan for Windows

It will enter the system through using any nefarious tactic at its disposal. This will usually include using bogus online malware scanners and seditious browser hijacking websites. These browser hijackers forcefully redirect users’ browsing and search sessions to compromised landing pages where Data Repair will be forcefully installed onto the PC through drive-by download tactics.

It will then initiate a fake system scan which will inform the user of various supposedly crippling errors rendering his PC inoperable. Shortly after this the user will experience be spammed by various fake system messages informing him of the same thing. Some of the more popular fake alerts to be on the lookout for include the following:

System Error
An error occurred while reading system files. Run a system diagnostic utility to check your hard disk drive for errors.

Hard Drive Failure
The system has detected a problem with one or more installed IDE / SATA hard disks. It is recommended that you restart the system.

Critical Error
Hard drive critical error. Run a system diagnostic utility to check your hard disk drive for errors. Windows can’t find hard disk space. Hard drive error.

If you read the above fake alerts carefully, you will see that you are dealing with an illegitimate application. This is because some of the alerts state that Windows can’t find the hard disk. Should this have been the case the PC would not be able to operate in the first place.

As a further attack on the system, Data Repair will prevent the user from running applications on the infected PC, and block his Internet access. This is done not only to further annoy the user but also to prevent him from running or downloading other applications which may be able to detect and remove Data Repair from the system. Other symptoms reported include poor system performance and increased erratic system behavior.

It is possible to disable these annoying symptoms by entering the following activation key into the rogue:

1203978628012489708290478989147

Users are advised that by simply entering the above key they will not have successfully eliminated the threat, but only disabled the symptoms. Users are still required to destroy Data Repair in order to restore the system’s security. This can best be done by making use of a powerful security tool which will not only erase Data Repair but also protect against similar attacks in future.

Download Spyware Removal Tool to Remove* Data Repair
  • Quick & tested solution for Data Repair removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Data Repair

Files associated with infection (Data Repair):

%UserProfile%\Desktop\Data Repair.lnk
%Temp%\smtmp\4
%Temp%\smtmp\3
%Temp%\smtmp\2
%Temp%\smtmp\1
%Temp%\smtmp\
%StartMenu%\Programs\Data Repair\Uninstall Data Repair.lnk
%StartMenu%\Programs\Data Repair\Data Repair.lnk
%StartMenu%\Programs\Data Repair\
%LocalAppData%\.exe

Processes to kill (Data Repair):

%LocalAppData%\.exe

Remove registry entries (Data Repair):

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU "MRUList"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" =
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.