• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Data Restore virus

Myantispyware team September 29, 2011    

Data Restore is a malicious program which pretends to be a computer defragmenter and system analysis software. It is from the same family of malware as Data Recovery, Master Utilities, PC Repair, System Repair, Windows XP Repair, Windows XP Fix, etc. It is promoted and installed itself on your computer without your permission and knowledge through the use of trojans or other malicious software. Moreover, the scammers may also distribute Data Restore on Twitter, My Space, Facebook, and other social networks. Please be careful when opening attachments and downloading files or otherwise you can end up with a rogue program on your PC.

When Data Restore is installed, it will perform a fake scan of your computer then tells you it has found numerous critical errors. Next, it will prompt you to pay for the fake software before it “repairs” your machine of the problems. Of course, all of these errors are a fake. So, you can safety ignore the false scan results.

While Data Restore is running, it will block legitimate Windows applcations on your computer and won’t let you download anything from the Internet. Moreover, it will display various fake critical errors alerts that the computer’s hard drive is corrupt in order to frighten you into purchasing this useless application. Some of the fake errors are:

The system has detected a problem with one or more installed IDE / SATA hard disks.
It is recommended that you restart the system.

Critical error
Windows can`t find disk space. Hard drive error.

System Restore
The system has been restored after a critical error. Data integrity and hard drive integrity verification required.

Windows – No Disk
Exception Processing Message 0×0000013.

Of course, all of these warnings are a fake. This is an attempt to make you think your computer in danger. Like false scan results you can safely ignore them.

As you can see, obviously, Data Restore is a scam, which created with only one purpose – to steal your money. Most important, don`t purchase the program! You need as quickly as possible to remove the malicious software. Follow the removal instructions below, which will remove Data Restore and any other infections you may have on your computer for free.

Use the following instructions to remove Data Restore infection

1

Click Start, Type in Search field %allusersprofile% and press Enter (if you use the Windows XP, then click Start, Run and type a command in Open field). It will open a contents of “ProgramData” folder (“All Users” folder for Windows XP).

2

Data Restore hides all files and folders, so you need to change some settings and thus be able to see your files and folders again. Click Organize, select ”Folder and search options”, open View tab (if you use Windows XP, then open Tools menu, Folder Options, View tab). Select “Show hidden files and folders” option, uncheck “Hide extensions for known file types”, uncheck “Hide protected operating files” and click OK button.

3

Open “Application Data” folder. This step only for Windows XP, skip it if you use Windows Vista or Windows 7.

4

Now you will see Data Restore associated files as shown below.

5

Basically, there will be files named with a series of numbers or letter (e.g. 2636237623.exe or JtwSgJHkjkj.exe), right click to it and select Rename (don`t rename any folders). Type any new name (123.exe) and press Enter.
You can to rename only files with .exe extension. Its enough to stop this malware from autorunning.

6

Reboot your computer.
 

7

Now you can unhide all files and folders that has been hidden by Data Restore. Click Start, type in Search field cmd and press Enter. Command console “black window” opens. Type cd \ and press Enter. Type attrib -h /s /d and press Enter. Close Command console.

8

If your Desktop is empty, then click Start, type in Search field %UserProfile%\desktop and press Enter. It will open a contents of your desktop.

9

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

10

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

11

If an update is found, it will download and install the latest version.

 

12

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window
13

Select Perform Quick Scan, then click Scan, it will start scanning your computer. This procedure can take some time, so please be patient.

14

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Data Restore remover
Malwarebytes Anti-malware, list of infected items
15

Make sure that everything is checked, and click Remove Selected for start Data Restore removal process. When disinfection is completed, a log will open in Notepad. Reboot your computer.

16

Data Restore may be bundled with TDSS trojan-rootkit, so you should run TDSSKiller to detect and remove this infection.

17

Download TDSSKiller from here and unzip to your desktop. Open TDSSKiller folder. Right click to tdsskiller and select rename. Type a new name (123myapp, for example). Press Enter. Double click the TDSSKiller icon. You will see a screen similar to the one below.


TDSSKiller
18

Click Start Scan button to start scanning Windows registry for TDSS trojan. If it is found, then you will see window similar to the one below.


TDSSKiller – Scan results
19

Click Continue button to remove TDSS trojan.

If you can`t to download or run TDSSKiller, then you need to use Combofix. Download Combofix. Close any open browsers. Double click on combofix.exe and follow the prompts. If ComboFix will not run, please rename it to myapp.exe and try again!

20

Your system should now be free of the Data Restore virus. If you need help with the instructions, then post your questions in our Spyware Removal forum.

Data Restore removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

Data Restore creates the following files and folders

%UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
%CommonAppData%\[RANDOM]
%CommonAppData%\~[RANDOM]
%UserProfile%\Desktop\Data Restore.lnk
%CommonAppData%\[RANDOM].exe
%Temp%\smtmp\
%Temp%\smtmp\1
%Temp%\smtmp\2
%Temp%\smtmp\3
%Temp%\smtmp\4

Note: %CommonAppData% is C:\Documents and Settings\All Users\Application Data (for Windows XP/2000) or C:\ProgramData (for Windows 7/Vista)

Data Restore creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\USE FORMSUGGEST = Yes
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\CERTIFICATEREVOCATION = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONBADCERTRECVING = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONZONECROSSING = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONES\3\1601 = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\WINTRUST\TRUST PROVIDERS\SOFTWARE PUBLISHING\STATE = 146944
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\CONTROL\SESSION MANAGER\PENDINGFILERENAMEOPERATIONS = \??\%CommonAppData%\[RANDOM].exe

Data Restore removal – Video instructions

Data Restore is basically clone of Windows XP Repair, so you can use the video guide below to remove this malware.

Malware removal Rogue Anti Spyware

 Previous Post

How to remove Advanced PC Shield 2012 virus

Next Post 

How to remove Security Sphere 2012 virus

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

12 Comments

  1. BettyBartos
    ― October 1, 2011 - 7:18 am  Reply

    thank you very much. this nasty thing is on our accounting computer and I can’t open quick books company folder. Anything that was on the desktop is un-openable, I can’t access contacts in windows mail, favorites in explorer appear to be gone, etc.At least I didn’t get sucked into the scam, to add insult to injury!

  2. noel
    ― October 2, 2011 - 11:14 am  Reply

    Dear sir,

    thank you so much for your help, you’re the expert, your instruction was very clear and accurate, i feel like an I.T. though i’m don’t really know how to fix this data restore virus. Thanks again and may God bless you.

    noel

  3. harel
    ― October 2, 2011 - 11:42 am  Reply

    thank you very much .
    i almost fall inyo the scam /
    it was very halpfull

  4. Michael
    ― October 3, 2011 - 5:11 am  Reply

    Super guide, thx.

  5. Chris B.
    ― October 3, 2011 - 6:12 pm  Reply

    Worked for me!!! Thanks!!!

  6. Maurice
    ― October 4, 2011 - 6:02 am  Reply

    WORKS! Thanx!

  7. Mats W
    ― October 4, 2011 - 9:16 am  Reply

    Thanks a lot, very easy guide.

  8. Michelle
    ― October 4, 2011 - 2:04 pm  Reply

    Thank you everything worked except. I still have the
    \data restore\ short cut on my desktop and in my \All
    Programs\ in start there are only a few of what is really
    On the pc. Not sure who to fix it.

  9. Nathan
    ― October 6, 2011 - 12:54 am  Reply

    Thank you so much for your help. You have no idea how much I appreciated it. God bless you.

    The only error that remains is that all the program folders on the start menu are empty. Any idea how to fix it?

    Thanks again.

  10. tommy
    ― October 6, 2011 - 5:04 am  Reply

    after I followed this tutorial, so why my software installation lost 🙁 including .exe file 🙁
    help please 🙁

  11. Michael
    ― October 6, 2011 - 9:30 am  Reply

    I get to the cmd black box and type in the commands, but everything that pops up keeps saying “access denied” followed by the file (I assume)

    What am I doing wrong?

  12. lori
    ― October 6, 2011 - 3:27 pm  Reply

    thank you so much!
    I was desperate today working on this pr.
    I have my account prg on the laptop and I was going insane.
    thx to your step by step guide from my phone i was starting to see the light at the end of the tunel.
    learned a lot from this experience.
    THX A LOT

Leave a Reply to tommy Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

How to reset Google Chrome settings to default
Best free malware removal tools
Best Free Malware Removal Tools 2025
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
remove chrome extension
How to remove Chrome extensions installed by enterprise policy

Recent Guides

How to remove Advanced PC Shield 2012 virus
How to remove OpenCloud Security virus
How to remove Data Recovery virus
How to remove Master Utilities virus
How to remove PC Repair virus

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.