File Restore

File Restore Description

ScreenshotFile Restore is a fake hard drive defragmentation tool from the FakeSysDef family, which is not able to repair system errors and other security issues. File Restore is distributed to the infected computer system by using a Trojan infection and invades your PC without your permission and knowledge. File Restore may create an impression of a reliable security program; however, it's a malware application, which only attempts to dupe you into thinking there were numerous registry errors detected on your computer system. Then, File Restore tries to convince you to purchase the bogus application to fix found system problems. Once installed, File Restore generates itself to start automatically every time you turn on your computer. Then, File Restore loads a fictitious scanner and pretends to be looking for computer threats and Windows Registry problems. File Restore creates some imaginary hard drive errors and security issues to scare you that your computer is seriously infected.

Known clones of File Restore include System Defragmenter, Ultra Defragger, HDD Control, Win HDD, Win Defrag, Win Defragmenter, Disk Doctor, Hard Drive Diagnostic, HDD Diagnostic, HDD Plus, HDD Repair, HDD Rescue, Smart HDD, Defragmenter, HDD Tools, Disk Repair, Windows Optimization Center, Scanner, HDD Low, Hdd Fix.

File Restore also displays numerous annoying security warning messages to inform you about hard disk drive errors. After that, File Restore will offer you to buy the imaginary registered license to repair PC problems. Never purchase and believe File Restore because it will destroy your machine and steal money. ESG's malware researchers strongly recommend you to uninstall File Restore immediately upon detection with a recognized and trustworthy anti-malware program.

Technical Information

Screenshots & Other Imagery

File Restore Image 1

File System Details

File Restore creates the following file(s):
# File Name Size MD5 Detection Count
1 %ALLUSERSPROFILE%&yb_Zog%.exe 1,019,904 dae81e01d143caaa70b126dc75971e58 6
2 %CommonAppData%\[RANDOM CHARACTERS_0].exe N/A
3 %CommonAppiData%\[RANDOM CHARACTERS_1].exe N/A
4 %Programs%\File Restore\File Restore.lnk N/A
5 %AppData%\Microsoft\Internet Explorer\Quick Launch\File_Restore.lnk N/A
6 %CommonAppData%\[RANDOM CHARACTERS_1] N/A
7 %Desktopdir%\File_Restore.lnk N/A
8 %Programs%\File Restore\Uninstall File Restore.lnk N/A

Registry Details

File Restore creates the following registry entry or registry entries:
File name without path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[RANDOM CHARACTERS_0].exe %CommonAppData%\[RANDOM CHARACTERS_0].exe

More Details on File Restore

The following messages associated with File Restore were found:
Critical error. Drive sector not found error
Critical Error. Hard drive conroller failure
Device initialization failed
Hard drive boot sector reading error
System blocks were not found
Error while relocating TARE sectors
The storage device has failed a self-test
The self-test procedure of the storage device has detected an irreparable errors.
SMART state is "Out of order" before the disk scan
Seek error. Sector not found
System message – Write Fault Error
A write command during the test has failed to complete. This may be due to a media or read/write error. The system generates an exception error when using a reference to an invalid system memory address.
This device cannot find enough free resources that it can use

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

HTML is not allowed.