• All Community
    • All Community
    • Forums
    • Blogs
Advanced

Not what you are looking for? Ask the experts!

Solved.
Kudos1 Stats

Restoro...safe or not?

Hi all, I recently installed Restoro, scanned my PC, paid for a licence and then had a few issues resolved on my PC. My Pc was immediately running much better, faster and rebooted in seconds. For me Restoro appears to have fixed multiple issues on my PC. I ran it for a second time after the first scan and reboot and it did not find any issues. So based on its behaviour it seems legit. I t was recommended from a legit website, otherwise I would have not touched it. However, Norton picked it up and removed it, identifying it as a low risk. Some research on the internet and Norton Forum suggests that some think it is a virus. I cannot get a definitive answer here, so can someone with a high Kudos or from Norton please advise me. Is it dodgy or not? As I said it worked wonders with my PC. What is the view of Norton?
Accepted Solution
Kudos2 Stats

Re: Restoro...safe or not?

Microsoft support policy for the use of registry cleaning utilities
https://support.microsoft.com/en-us/help/2563254/microsoft-support-policy-for-the-use-of-registry-cleaning-utilities#:~:text

EQ71:
[...] the issues it identified on your test PC... were they false positives...as in completely fabricated?

Registry Results -
registry keys that Restoro wanted to "fix" appeared to be Dell tools.  I did not want Restoro "fix".  Just me. 
for example: 

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\DellRemoteAssist\DellRemoteAssist.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAppLauncher.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAppWire.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistUI.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\WindowsStore_SB.url
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\RNService.dll
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\RNUtils.dll
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe.config
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe

Granted, registry keys may be dross.  
Granted, not all Dell users like Dell tools.   

and Threats Results -  I did not want Restoro "fix".  Just me.  

and Junk Results appeared to be Temp files.  I did not want Restoro "fix".  Just me.  
for example:

C:\Users\bjm\AppData\Local\Temp\nst951D.tmp325632
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\registry.dll25088
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\stack.dll10752
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\rCrypt.dll289792
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp325632
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\registry.dll25088
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\stack.dll10752
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\rCrypt.dll289792
C:\Users\bjm\AppData\Local\Temp\nsp21F1.tmp325632

and Stability Results appeared to be Esent reports.  I did not want Restoro "fix".  Just me. 
for example:

Application: esent
Crash date: 2020/08/01/ 0:55
Crash date: 2020/07/31/ 19:5
Crash date: 2020/07/31/ 18:56
Crash date: 2020/07/31/ 15:45
Crash date: 2020/07/31/ 15:38
Crash date: 2020/07/31/ 15:9
Crash date: 2020/07/31/ 2:6
Crash date: 2020/07/31/ 0:58
Crash date: 2020/07/31/ 0:40
Crash date: 2020/07/30/ 20:52

Replies

Kudos0

Re: Restoro...safe or not?

Report a suspected incorrect detection to NortonLifeLock
This document instructs on how to report a false positive or a false negative to NortonLifeLock through the online submission form.

https://support.norton.com/sp/en/us/home/current/solutions/v126152382


https://community.norton.com/en/forums/restoro

https://community.norton.com/en/forums/how-do-i-get-rid-restoroprotectionexe

https://safeweb.norton.com/report/show_mobile?name=restoro.com

https://www.trustpilot.com/review/restoro.com


Is Restoro a safe website?
No. It's not Microsoft and it's not legitimate.
Even if it weren't a scam, all such sites that claim to fix or improve things at best are useless. They are all more likely to create problems than to solve them.

https://answers.microsoft.com/en-us/windows/forum/all/is-restoro-a-safe-website/33a40afd-74ed-4e9d-b57e-201e65cda0ad 

Restoro - is it genuine?
I purchased a new desktop HP computer and have now had it for 5 days.  I noticed that it was quite slow for a new computer, then yesterday a window opened to say I had problems on my computer and a programme called Restoro (said its origin was on the hard disk) appeared and checked my computer.  Results shown there were faults on my computer and when I clicked on repair it wanted payment.  Is this a valid programme, or not?  If it is, I very much resent the fact that a brand new computer is slow and then you are charged to repair it.  I would very much appreciate comments on this, please.

https://answers.microsoft.com/en-us/windows/forum/all/restoro-is-it-genuine/89e6fd65-2626-4ea2-b270-d165bb1afcfc 


Removal instructions for Restoro
The Malwarebytes research team has determined that Restoro is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.

https://forums.malwarebytes.com/topic/235321-removal-instructions-for-restoro/ 


Restoro offers Advanced Repair software for your Windows PC
https://reviews.thewindowsclub.com/restoro-review-download/

RESTORO – Is It Safe & Legit? Restoro Uninstall
https://howtofix.guide/restoro-uninstall/

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

Hmm...thanks for that BJM, I was hoping you would chime in...a mixed bag I see. I did go over the Norton forum and had read the Trust Pilot reviews aswell.....I am after an opinion. It seems legit, if it were ransom ware or a virus then surely Norton would be very clear and give it a High risk rating rather than low risk based on peoples aggregate experience. It does do things to the registry which may explain the suspicious activity.....but I am not an expert. What do you think? Again based on my experience I see a significant improvement to my PC's performance. In your opinion and experience do you think it is safe to release from quarantine based on what you know about it?
Kudos0

Re: Restoro...safe or not?

What is the view of Norton?

Maybe, ask NortonLifeLock

Report a suspected incorrect detection to NortonLifeLock
This document instructs on how to report a false positive or a false negative to NortonLifeLock through the online submission form.

https://support.norton.com/sp/en/us/home/current/solutions/v126152382


Hmm...thanks for that BJM, I was hoping you would chime in...a mixed bag I see. [...] What do you think? Again based on my experience I see a significant improvement to my PC's performance. In your opinion and experience do you think it is safe to release from quarantine based on what you know about it?

FWIW ~ 
I had Restoro installed just long enough to run Restoro preliminary scan & take screen pics -
I did not exercise all Restoro features - 
I did not run Restoro - 
I did not run Restoro real-time monitoring - 

Enable real-time monitoring                                
*When enabled, Restoro® real-time monitoring of malware applications and newly
 downloaded files will continue to run in the background after you close the program
 and notify you on infected files

https://community.norton.com/en/comment/8410641#comment-8410641

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

Ok submitted, thanks for your help, I guess I understand your reluctance to say its fine....hopefully Norton will give me a resolution. Enjoy your weekend!
Kudos1 Stats

Re: Restoro...safe or not?

However, Norton picked it up and removed it, identifying it as a low risk.

Care to share Norton detection information? 
What did Norton pick up and remove?
Norton did not object to Restoro install on your machine?
What did Norton object to on your machine? 


Norton detection criteria may not satisfy all users, all the time -
PUP/PUA ... as you know are "potentially unwanted programs"

By classifying these programs as just “potentially unwanted programs,” antimalware software creators are attempting to shield themselves from legal action while detecting software most people don’t want on their computers.

Whether an antimalware — or antivirus — application chooses to flag and detect PUPs is up to that individual engine. Some security software makers are more focused on malware, while others — Malwarebytes, for example — are more serious about detecting and removing PUPs.

https://www.howtogeek.com/232791/pups-explained-what-is-a-potentially-unwanted-program/


FWIW ~ Items rated as a PUP/PUA - which does not mean malware. A PUA can download and install other software that might turn out to be, indeed, malicious. However, PUA can be installed at the user's discretion. The signature detection is to bring the file to the user's attention.

What some users consider a PUA, other users will not; what one AV company rates as a PUA, another may not.

In general, be more vigilant and discerning. PUAs in particular usually install with your consent, and your consent can often be implied when you take shortcuts like a default installation, fail to read all the installation options presented, fail to read Terms & Privacy & EULA.

This post is provided “AS IS" with no guarantees or warranties.  ~ YMMV

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

I think below is what you were after, as I recall, the installation file was scanned and given the all clear by Norton, green lit all the way and then the installation and the webpage were unflagged. I have included the original page I got the link from...right at the bottom of the page is what I now recognise as an add and not part of the article as I assumed.... https://windowsreport.com/windows-store-games-wont-download-windows-10/ Filename: PUA.Superfluss Full Path: Not Available ____________________________ ____________________________ On computers as of  Not Available Last Used  31/07/2020 at 18:27:57 Startup Item  No Launched  No Threat type: Security Risk. Programs that pose a security or privacy risk and are not already classified as malicious. ____________________________ PUA.Superfluss Locate Unknown It is unknown how many users in the Norton Community have used this file. Unknown This file release is currently not known. Low This file risk is low. ____________________________ Source: External Media ____________________________ File Actions File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Help & Support.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Privacy Policy.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Restoro.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Run in safe mode.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Terms of Use.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Uninstall Instructions.lnk Threat Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restoro\ Uninstall.lnk Threat Removed File: C:\ProgramData\Restoro\AV\idx\ module-vdf.info Threat Removed File: C:\ProgramData\Restoro\AV\ aebb.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aecore.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aecrypto.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aedroid.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aedroid_gwf.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aeemu.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeexp.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeexp_gwf.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aegen.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aehelp.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeheur.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeheur_agen.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aeheur_gwf.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aeheur_mv.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aelibinf.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aelibinf_db.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aelidb.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aeml.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aemobile.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeoffice.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeoffice_gwf.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aepack.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aerdl.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aesbx.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aescn.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aescript.dll Threat Removed File: C:\ProgramData\Restoro\AV\ aeset.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aevdf.dat Threat Removed File: C:\ProgramData\Restoro\AV\ aevdf.dll Threat Removed File: C:\ProgramData\Restoro\AV\ apcfile.dll Threat Removed File: C:\ProgramData\Restoro\AV\ apc_random_id_generator.exe Threat Removed File: C:\ProgramData\Restoro\AV\ avupdate.exe Threat Removed File: C:\ProgramData\Restoro\AV\ avupdate.log Threat Removed File: C:\ProgramData\Restoro\AV\ avupdate_msg.avr Threat Removed File: C:\ProgramData\Restoro\AV\ cacert.crt Threat Removed File: C:\ProgramData\Restoro\AV\ HBEDV.KEY Threat Removed File: C:\ProgramData\Restoro\AV\ local000.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ master.idx Threat Removed File: C:\ProgramData\Restoro\AV\ msvcr120.dll Threat Removed File: C:\ProgramData\Restoro\AV\ productname.dat Threat Removed File: C:\ProgramData\Restoro\AV\ savapi.dll Threat Removed File: C:\ProgramData\Restoro\AV\ savapi.exe Threat Removed File: C:\ProgramData\Restoro\AV\ savapi_restart.exe Threat Removed File: C:\ProgramData\Restoro\AV\ savapi_stub.exe Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00000.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00001.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00002.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00003.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00004.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00005.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00006.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00007.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00008.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00009.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00010.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00011.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00012.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00013.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00014.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00015.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00016.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00017.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00018.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00019.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00020.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00021.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00022.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00023.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00024.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00025.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00026.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00027.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00028.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00029.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00030.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00031.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00032.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00033.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00034.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00035.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00036.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00037.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00038.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00039.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00040.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00041.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00042.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00043.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00044.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00045.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00046.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00047.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00048.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00049.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00050.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00051.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00052.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00053.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00054.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00055.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00056.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00057.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00058.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00059.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00060.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00061.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00062.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00063.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00064.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00065.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00066.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00067.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00068.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00069.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00070.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00071.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00072.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00073.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00074.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00075.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00076.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00077.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00078.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00079.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00080.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00081.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00082.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00083.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00084.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00085.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00086.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00087.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00088.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00089.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00090.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00091.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00092.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00093.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00094.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00095.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00096.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00097.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00098.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00099.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00100.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00101.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00102.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00103.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00104.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00105.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00106.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00107.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00108.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00109.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00110.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00111.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00112.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00113.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00114.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00115.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00116.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00117.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00118.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00119.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00120.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00121.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00122.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00123.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00124.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00125.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00126.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00127.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00128.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00129.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00130.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00131.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00132.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00133.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00134.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00135.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00136.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00137.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00138.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00139.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00140.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00141.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00142.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00143.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00144.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00145.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00146.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00147.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00148.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00149.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00150.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00151.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00152.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00153.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00154.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00155.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00156.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00157.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00158.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00159.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00160.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00161.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00162.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00163.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00164.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00165.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00166.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00167.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00168.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00169.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00170.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00171.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00172.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00173.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00174.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00175.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00176.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00177.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00178.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00179.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00180.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00181.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00182.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00183.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00184.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00185.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00186.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00187.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00188.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00189.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00190.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00191.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00192.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00193.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00194.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00195.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00196.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00197.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00198.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00199.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00200.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00201.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00202.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00203.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00204.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00205.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00206.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00207.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00208.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00209.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00210.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00211.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00212.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00213.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00214.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00215.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00216.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00217.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00218.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00219.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00220.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00221.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00222.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00223.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00224.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00225.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00226.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00227.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00228.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00229.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00230.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00231.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00232.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00233.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00234.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00235.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00236.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00237.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00238.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00239.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00240.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00241.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00242.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00243.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00244.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00245.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00246.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00247.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00248.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00249.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00250.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00251.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00252.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00253.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00254.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00255.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbvRei.vdf Threat Removed File: C:\ProgramData\Restoro\bin\Results\ restoro-service-updater.log Threat Removed File: C:\ProgramData\Restoro\bin\ conf.res Threat Removed File: C:\ProgramData\Restoro\bin\ scan-result.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\After\ HKEY_LOCAL_MACHINE_SOFTWARE Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\After\ HKEY_LOCAL_MACHINE_SYSTEM Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\Before\ HKEY_LOCAL_MACHINE_SOFTWARE Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\Before\ HKEY_LOCAL_MACHINE_SYSTEM Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ installed.rec Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ junk.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ junk_results.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ out.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ registry.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ RegistryScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ restoro.2.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ restoro.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ stability.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ StabilityScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ vars.res Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ installed.rec Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ junk.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ junk_results.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ out.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ registry.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ RegistryScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ restoro.2.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ restoro.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ StabilityScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1139\ vars.res Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\After\ HKEY_LOCAL_MACHINE_SOFTWARE Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\After\ HKEY_LOCAL_MACHINE_SYSTEM Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\Before\ HKEY_LOCAL_MACHINE_SOFTWARE Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\Before\ HKEY_LOCAL_MACHINE_SYSTEM Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ installed.rec Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ junk.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ junk_results.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ out.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ registry.html Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ RegistryScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ restoro.2.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ restoro.log Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ StabilityScanRes.xml Threat Removed File: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ vars.res Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\images\ btn.jpg Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\images\ malware.jpg Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\images\ send.png Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\images\ star.png Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\scripts\ jquery.js Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\scripts\ main.js Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\assets\styles\ main.css Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\ after-repair-main.html Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\ after-repair.html Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\ AfterRepairLauncher.exe Threat Removed File: C:\ProgramData\Restoro\revert\after-restart\ AR.lnk Threat Removed File: C:\ProgramData\Restoro\revert\ Restoro.und Threat Removed File: C:\ProgramData\Restoro\revert\ Restoro.val Threat Removed File: C:\ProgramData\Restoro\revert\ RevertTool.exe Threat Removed File: C:\ProgramData\Restoro\revert\ undo.stt Threat Removed File: C:\ProgramData\Restoro\Temp\20200731_1623\Installer\ Restoro Threat Removed File: C:\ProgramData\Restoro\Temp\20200731_1623\ autorun.dat Threat Removed File: C:\ProgramData\Restoro\Temp\20200731_1623\ RepFiles.lst Threat Removed File: C:\ProgramData\Restoro\ conf.res Threat Removed File: C:\ProgramData\Restoro\ crf.res Threat Removed File: C:\ProgramData\Restoro\ fpr.res Threat Removed File: C:\ProgramData\Restoro\ restoro.ext Threat Removed File: C:\ProgramData\Restoro\ TechSupportApp.ini Threat Removed File: C:\Program Files\Restoro\bin\ RestoroApp.exe Threat Removed File: C:\Program Files\Restoro\ ax.dll Threat Removed File: C:\Program Files\Restoro\ ax.lza Threat Removed File: C:\Program Files\Restoro\ engine.dll Threat Removed File: C:\Program Files\Restoro\ engine.lza Threat Removed File: C:\Program Files\Restoro\ LZMA.EXE Threat Removed File: C:\Program Files\Restoro\ msvcr120.dll Threat Removed File: C:\Program Files\Restoro\ Restoro Help & Support.url Threat Removed File: C:\Program Files\Restoro\ Restoro Privacy Policy.url Threat Removed File: C:\Program Files\Restoro\ Restoro Terms of Use.url Threat Removed File: C:\Program Files\Restoro\ Restoro Uninstall Instructions.url Threat Removed File: C:\Program Files\Restoro\ Restoro.exe Threat Removed File: C:\Program Files\Restoro\ RestoroAM.exe Threat Removed File: C:\Program Files\Restoro\ Restoroicon.ico Threat Removed File: C:\Program Files\Restoro\ RestoroMain.exe Threat Removed File: C:\Program Files\Restoro\ RestoroSafeMode.exe Threat Removed File: C:\Program Files\Restoro\ Restoro_SafeMode.ico Threat Removed File: C:\Program Files\Restoro\ Restoro_uninstall.ico Threat Removed File: C:\Program Files\Restoro\ Restoro_website.ico Threat Removed File: C:\Program Files\Restoro\ savapi.dll Threat Removed File: C:\Program Files\Restoro\ TechSupportApp.exe Threat Removed File: C:\Program Files\Restoro\ uninst.exe Threat Removed Directory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Restoro Threat Removed Directory: C:\ProgramData\Restoro\AV\ idx Threat Removed Directory: C:\ProgramData\Restoro\ AV Threat Removed Directory: C:\ProgramData\Restoro\bin\ Results Threat Removed Directory: C:\ProgramData\Restoro\ bin Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ After Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1106\ Before Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\ RUN20200731_1106 Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\ RUN20200731_1139 Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ After Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\RUN20200731_1623\ Before Threat Removed Directory: C:\ProgramData\Restoro\Results\EXE2.0.1.8\ RUN20200731_1623 Threat Removed Directory: C:\ProgramData\Restoro\Results\ EXE2.0.1.8 Threat Removed Directory: C:\ProgramData\Restoro\ Results Threat Removed Directory: C:\ProgramData\Restoro\revert\after-restart\assets\ images Threat Removed Directory: C:\ProgramData\Restoro\revert\after-restart\assets\ scripts Threat Removed Directory: C:\ProgramData\Restoro\revert\after-restart\assets\ styles Threat Removed Directory: C:\ProgramData\Restoro\revert\after-restart\ assets Threat Removed Directory: C:\ProgramData\Restoro\revert\ after-restart Threat Removed Directory: C:\ProgramData\Restoro\ revert Threat Removed Directory: C:\ProgramData\Restoro\Temp\20200731_1623\ DownloaderTemp Threat Removed Directory: C:\ProgramData\Restoro\Temp\20200731_1623\ Installer Threat Removed Directory: C:\ProgramData\Restoro\Temp\ 20200731_1623 Threat Removed Directory: C:\ProgramData\Restoro\ Temp Threat Removed Directory: C:\ProgramData\ Restoro Threat Removed Directory: C:\Program Files\Restoro\ bin Threat Removed Directory: C:\Program Files\ Restoro Threat Removed ____________________________ File Thumbprint - SHA: Not available File Thumbprint - MD5: Not available
Kudos1 Stats

Re: Restoro...safe or not?

EQ71:
File Thumbprint - SHA: Not available
File Thumbprint - MD5: Not available

Hi @EQ71,
I was hoping for hash checksum -  


EQ71:
[...]
C:\ProgramData\Restoro\AV\ avupdate.exe Threat Removed File: C:\ProgramData\Restoro\AV\ avupdate.log Threat Removed File: C:\ProgramData\Restoro\AV\ avupdate_msg.avr Threat Removed File: C:\ProgramData\Restoro\AV\ cacert.crt Threat Removed File: C:\ProgramData\Restoro\AV\ HBEDV.KEY Threat Removed File: C:\ProgramData\Restoro\AV\ local000.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ master.idx Threat Removed File:

C:\ProgramData\Restoro\AV\ xbv00113.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00114.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00115.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00116.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00117.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00118.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00119.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00120.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00121.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00122.vdf Threat Removed File: C:\ProgramData\Restoro\AV\ xbv00123.vdf Threat Removed File:
[...]

Maybe, Norton detected Restoro virus definitions as threat?   
Malware definitions may contain bits of code that resemble malware to other security solutions? 

IMPORTANT NOTE: Using more than one anti-virus program with real-time protection simultaneously is not advisable. 

Even if one of the anti-virus programs is disabled for use as a stand-alone on demand scannerit can still affect the other and cause conflicts. Anti-virus software components insert themselves deep into the operating systems core where they install kernel mode drivers that load at boot-up regardless of whether real-time protection is enabled or not. Thus, using multiple anti-virus solutions can result in kernel mode conflicts causing system instability, catastrophic crashes, slow performance and waste vital system resources. When actively running in the background while connected to the Internet, each anti-virus may try to update their definition databases at the same time. As the programs compete for resources required to download the necessary files this often can result in sluggish system performance or unresponsive behavior.

When scanning engines are initiated, each anti-virus may interpret the activity of the other as suspicious behavior and there is a greater chance of them alerting you to a "false positive". If one finds a virus or a suspicious file and then the other also finds the same, both programs will be competing over exclusive rights on dealing with that threat. Each anti-virus may attempt to remove the offending file and quarantine it at the same time resulting in a resource management issue as to which program gets permission to act first. If one anit-virus finds and quarantines the file before the other one does, then you may encounter the problem of both wanting to scan each other's zipped or archived files and each reporting the other's quarantined contents. This can lead to a repetitive cycle of endless alerts that continually warn you that a threat has been found after it has already been neutralized.

Anti-virus scanners use virus definitions to check for malware and these can include a fragment of the virus code which may be recognized by other anti-virus programs as the virus itself. Because of this, many anti-virus vendors encrypt their definitions so that they do not trigger a false alarm when scanned by other security programs. Other vendors do not encrypt their definitions and they can trigger false alarms when detected by the resident anti-virus.

Further, dual installation is not always possible because most of the newer anti-virus programs will detect the presence of another and may insist that it be removed prior to installation. If the installation does complete with another anti-virus already installed, you may encounter issues like system freezing, unresponsiveness or similar symptoms as described above while trying to use it. In some cases, one of the anti-virus programs may even get disabled by the other.

To avoid these problems, use only one anti-virus solution. Deciding which one to remove is your choice. Be aware that you may lose your subscription to that anti-virus program's virus definitions once you uninstall that software.

Microsoft and major Anti-virus vendors recommend that you install and run only one anti-virus program at a time.

https://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/?p=2316629

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

EQ71:
[...] I have included the original page I got the link from...right at the bottom of the page is what I now recognise as an add and not part of the article as I assumed.... https://windowsreport.com/windows-store-games-wont-download-windows-10/

Okay, I had to turn off my content blocker to see:

https://cloud.restoro.com/download/rh/Restoro.exe
Downloaded File Restoro.exe from restoro.com
File Thumbprint - SHA:
55757e1a0b20f880ae146b3409ecdb0d40eeb170d0562ae3028037b56b060849
File Thumbprint - MD5:
5755d55aad262408a116bf77ec8da51d

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

EQ71:
Filename: PUA.Superfluss 

PUA.Superfluss is a generic detection for many individual but varied potentially unwanted applications for which specific definitions have not been created. A generic detection is used because it protects against many potentially unwanted applications that share similar characteristics. [source google] 


What is a PUA (Potentially Unwanted Application) or PUP (Potentially Unwanted Program)?
https://us.norton.com/internetsecurity-malware-what-are-puas-potentially-unwanted-applications.html

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

Sorry first time poster...need to learn how to do that, (how can I get you a hash file?)...Yea likewise, I had temp allowed the page earlier to fully view the content on the page....Yea that makes sense re only using 1 AV. I do only use Norton...I understand Restoro has an AV component, I am only interested in the system tuning/repair....but yea prob spot on re Norton detecting the definitions inside of Restoro, So yea, you downloaded, came up safe from Norton but 4 engines detected this file....? I am actually learning so much here, appreciate you taking the time.
Kudos0

Re: Restoro...safe or not?

EQ71:
Sorry first time poster...need to learn how to do that, (how can I get you a hash file?)

Sorry, I meant I was hoping that Norton generated a hash -
Norton reported hash Not available

File Thumbprint - SHA: Not available
File Thumbprint - MD5: Not available 

 So yea, you downloaded, came up safe from Norton but 4 engines detected this file....? 

4/72 VirusTotal engines detected "Restoro Downloader" -
https://www.virustotal.com/gui/file/55757e1a0b20f880ae146b3409ecdb0d40eeb170d0562ae3028037b56b060849/detection

Note: VT engines may use the same source - same criteria. 
4/72 (at this time) IMO is not a resounding conviction.  Just saying.

NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

FWIW ~ as test -
 - ran Restoro Downloader from [here]

Filename: RestoroSetup.exe
Threat name: Trojan.Gen.2Full Path: C:\Users\bjm\AppData\Local\Temp\RestoroSetup.exe

On computers as of 
7/31/2020 at 8:47:39 PM

Last Used 
7/31/2020 at 8:49:39 PM

Startup Item 
No

Launched 
No

Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.

RestoroSetup.exe Threat name: Trojan.Gen.2
Locate

Very Few Users
Fewer than 5 users in the Norton Community have used this file.

Very New
This file was released less than 1 week  ago.

High
This file risk is high.

http://cloud.restoro.com/download/2018a/RestoroSetup64.exe
Downloaded File  from restoro.com
Source: External Media

RestoroSetup.exe

File Actions

File: C:\Users\bjm\AppData\Local\Temp\ RestoroSetup.exe Removed

File Thumbprint - SHA:
fa76ebaac43593273124fd45e686003b71a233d35f00900e7ded0848157bf6ff
File Thumbprint - MD5:
38e458d436de9ff89fe48b1f2e050b39
NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

FWIW ~ as test -

NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

http://www.restoro.com/how-does-it-work/
NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

So is this a different file from a different source? The read from Norton is completely different. I notice that the installer was again fine. Could the AV be detecting the definitions in the package itself? Norton is very clear here calling it a Trojan.
Kudos0

Re: Restoro...safe or not?

File 1 and File 2 appear to be from have diff thumbprints so am I understanding this correctly that they are 2 diff files....implying that 1 is OK but the other is bad (Trojan)? File 1? File Thumbprint - SHA: 55757e1a0b20f880ae146b3409ecdb0d40eeb170d0562ae3028037b56b060849 File Thumbprint - MD5: 5755d55aad262408a116bf77ec8da51d File 2? File Thumbprint - SHA: fa76ebaac43593273124fd45e686003b71a233d35f00900e7ded0848157bf6ff File Thumbprint - MD5: 38e458d436de9ff89fe48b1f2e050b39
Kudos1 Stats

Re: Restoro...safe or not?

File Thumbprint - SHA: 55757e1a0b20f880ae146b3409ecdb0d40eeb170d0562ae3028037b56b060849 represents the Restoro Downloader file. 
File Thumbprint - SHA: fa76ebaac43593273124fd45e686003b71a233d35f00900e7ded0848157bf6ff represents the Restoro Setup file.   

Restoro Downloader file (Restoro.exe) is the small file downloaded from windowsreport.com page.  Upon execution of the small Restoro.exe file from my desktop.   Restoro SetUp (RestoroSetup.exe) program is launched.    Restoro Setup file pulls and installs the full Restoro program. 

File thumbprints are different, as you know, because the files are different.   

Note:
I ran Restoro free version. 
I did not run Restoro Start Repair. 

Sorry, I cannot reproduce your @EQ71 Restoro experience as noted [here], my side.  I did not pay for a licence nor run Start Repair.   I reviewed the items that Restoro reported from their free scan ... but, did not want Restoro program to remove registry keys, junk files, etc. on my machine.  Just me.  

NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

8/72 VirusTotal engines report Restoro Setup thumbprint, at this time -
https://www.virustotal.com/gui/file/fa76ebaac43593273124fd45e686003b71a233d35f00900e7ded0848157bf6ff/detection

Note: VT engines may use the same source - same criteria. 

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

Thanks for that bjm. I think your saying that the initial installation can be Ok but the installed programme can then import a nasty later on. Equally Norton flags it to bring to my attention in case I am unaware of it being installed...so it may not necessarily be bad. I understand you don't want to purchase a licence to test the clean up....the issues it identified on your test PC... were they false positives...as in completely fabricated?....Trust pilot gives this an Ok rating but I know from personal experience that Trust Pilot is NOT to be trusted. I KNOW that they delete legit negative reviews that are fair and honest (if you pay a fee of some sort apparently). I guess for the moment i have to wait and see what comes back from Norton, although even if they say it is safe there is a lot of smoke here.....and I most definatley am very discerning about what goes on my machine. A pity as it appears to be a great app that definatley fixed my PC. A pity they have to screw that up by acting in a shady way. Somebody should make an app that does what Restoro is supposed to do...
Accepted Solution
Kudos2 Stats

Re: Restoro...safe or not?

Microsoft support policy for the use of registry cleaning utilities
https://support.microsoft.com/en-us/help/2563254/microsoft-support-policy-for-the-use-of-registry-cleaning-utilities#:~:text

EQ71:
[...] the issues it identified on your test PC... were they false positives...as in completely fabricated?

Registry Results -
registry keys that Restoro wanted to "fix" appeared to be Dell tools.  I did not want Restoro "fix".  Just me. 
for example: 

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\DellRemoteAssist\DellRemoteAssist.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAppLauncher.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAppWire.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistUI.exe
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\WindowsStore_SB.url
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\RNService.dll
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\RNUtils.dll
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe.config
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe

Granted, registry keys may be dross.  
Granted, not all Dell users like Dell tools.   

and Threats Results -  I did not want Restoro "fix".  Just me.  

and Junk Results appeared to be Temp files.  I did not want Restoro "fix".  Just me.  
for example:

C:\Users\bjm\AppData\Local\Temp\nst951D.tmp325632
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\registry.dll25088
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\stack.dll10752
C:\Users\bjm\AppData\Local\Temp\nst951D.tmp\rCrypt.dll289792
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp325632
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\registry.dll25088
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\stack.dll10752
C:\Users\bjm\AppData\Local\Temp\nsqF142.tmp\rCrypt.dll289792
C:\Users\bjm\AppData\Local\Temp\nsp21F1.tmp325632

and Stability Results appeared to be Esent reports.  I did not want Restoro "fix".  Just me. 
for example:

Application: esent
Crash date: 2020/08/01/ 0:55
Crash date: 2020/07/31/ 19:5
Crash date: 2020/07/31/ 18:56
Crash date: 2020/07/31/ 15:45
Crash date: 2020/07/31/ 15:38
Crash date: 2020/07/31/ 15:9
Crash date: 2020/07/31/ 2:6
Crash date: 2020/07/31/ 0:58
Crash date: 2020/07/31/ 0:40
Crash date: 2020/07/30/ 20:52
NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

..........And that, Bjm is the decider. If it is providing false positives, (just confirm that the install you ran was from the link I provided|) that is No Bueno! I need go no further. Microsoft Policy was also clarifying....although frankly Microsoft have a very low trust factor (for me). False positives, reported as a Virus and being detected as such by more and more AV's.....Install file seems safe but can in the future download evil on to your system...I think this stays in quarantine. (or best yet don't download it)....Like I say though ....a damn shame as so far the product worked very well!....I just don't trust it....way way too much smoke for there to be no fire here......If I was the owner and this was a genuine product I would recognise that brand name Restoro was burnt and dump it followed by a rebrand! Thanks Bjm!
Kudos0

Re: Restoro...safe or not?

EQ71:
..........And that, Bjm is the decider. If it is providing false positives, (just confirm that the install you ran was from the link I provided|)

Yes, I decided to not run Restoro "fix".  
I'm not claiming Restoro free scan reported "false positives".   
Yes, I started from windowsreport.com page here > https://community.norton.com/en/comment/8451531#comment-8451531

I do not have long term use experience to qualify Restoro one way or the other.  
I'm just not comfortable with Restoro features. Just me.
I've no experience with * Powered by Reimage Patented Technology. 

https://www.reimageplus.com/patented-technology/
http://www.restoro.com/how-does-it-work/


Sorry -----
Lets hear from Community 

NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

Maybe, Norton detected Restoro normal legit functions [here] -
 * Powered by Reimage Patented Technology 

How does Restoro fix Windows?
The repair will deactivate then quarantine all Malware found then remove virus damage.
All System Files, DLLs, and Registry Keys that have been corrupted or damaged will be replaced with new healthy files from our continuously updated online database.
The online database is comprised of over 25,000,000 updated essential components that will replace any damaged or missing file on a Windows operating system with a healthy version of the file so that your PC's performance, stability & security will be restored and even improve.

http://www.restoro.com/how-does-it-work/

Maybe, Norton + Restoro users need to add mutual exclusions -  
Maybe, Norton + Restoro simply do not play well together -

Lets hear from Community

NortonLifeLock Community is primarily user-to-user help
Kudos0

Re: Restoro...safe or not?

The online database is comprised of over 25,000,000 updated essential components that will replace any damaged or missing file on a Windows operating system with a healthy version of the file so that your PC's performance, stability & security will be restored and even improve. 

...And if I could trust that those replacements were legit.....and not malicious I would be a confirmed user. Like I said, to much smoke here....they may have come up with an revolutionary outstanding product.....but at this point I have to suck up the licence that I paid for, block further payments and keep it quarantined/delete it.....additionally more and more AV's are recognising it as a nasty....? Again...sucks because it made my PC fly!!

Kudos1 Stats

Re: Restoro...safe or not?

Again...sucks because it made my PC fly!!

Maybe, Norton should be removed before running Restoro repair.  IDK 

....but at this point I have to suck up the licence that I paid for,

https://www.restoro.com/refund-policy/


Always best practice is recent system image backup - 

NortonLifeLock Community is primarily user-to-user help
Kudos1 Stats

Re: Restoro...safe or not?

I had a look at the link to Microsoft on cleaning up the Registry and it's a good straight-forward "Don't do it"!

I do use CCleaner that includes a Registry Cleaner section but I refrain from using it although I sometimes run it to see what it thinks is wrong with my Windows 10 Regisitry! But I don't tell it to clean up.

I have tried doing that in the past in order to see how it works (it didn't do any damage that time so far as I could see back then) and it does in fact offer both create a System Restore Point and to back up the deleted items so you can change back which Microsoft stress is essential if you are going to run a Registry Cleaner.

I noted that their link to "How to back up your Registry" did not take me to that for Windows 10 at least but to a whole host of other items of information.

Hugh
Kudos0

Re: Restoro...safe or not?

DO NOT USE 'RESTORO'

I think it drops this after a few reboots...so it is stealthy and almost grooms the user into trusting it. I am never using this software again.

File Attachment: