When FakeAV.DataRecovery is executed, it performs the following activities:
It installs a the fake rogueware application "Data Recovery- (S.M.A.R.T Check)" (shown below)
Next, it will drop a copy of itself at the following location:
"%ALLUSERSPROFILE%\Application Data"
As pictured below, the rogueware will display false alerts in attempt to trick users into purchasing the software. Thirtyseven4 Antivirus fully removes this threat and the Thirtyseven4 Rogueware Remover tool has also been updated to detect and remove the infection.
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4