Lite PDF Reader virus - How to remove

Lite PDF Reader adware virus is officially described as a free, trusted standard for viewing, printing, signing, and annotating PDFs. It is the PDF reader from hell just like tools like and We initiated several scans of LitePDFReader1.0.0.2_Setup.exe and the results ranged from it being regarded as a Trojan or adware infection (VirusTotal analysis). Different detecters of malware labeled it Trojan.DownLoader25.33956, Win32:Malware-gen and AdWare.Agent.

Lite PDF Reader virus is more dangerous than it might seem

Even though in the official website of Lite PDF Reader virus, the tool is described as completely free of charge, the installation process reveals a different scenario. It turns out that the tool is free of use only if users agree to reset their default browsers’ startup page to browser hijacker. If not, then the tool is free only for 30 days.

Lite PDF Reader virusFurthermore, we ran a more thorough and explicit investigation of this Setup file through (Hybrid Analysis) tools and it provided more evidence that the Lite PDF Reader virus is indeed malicious. The threat score of this file reaches 100/100% because of the multiple alarming features and processes it conveys. First of all, one of the most disturbing facts is that it will contain abilities to register/read input devices, which is often used for (Key-logging). It also modifies auto-execute functionalities by setting/creating a value in the registry.

According to the analysis, the Lite PDF Reader malware tool will be able to spawn a lot of malicious processes and even check for the presence of a forensics tool. It also has been determined to launch the MountPointManager which is frequently exploited for the purpose of detecting other infection locations. Besides these changes, the tool will also create a resource fork to become even more evasive from detection. This malware also has capacities to modify proxy settings and query sensitive IE security settings.

Lite PDF Reader virus contacts three hosts (from US and European Union) and makes DNS (DNS Query Process) requests to,,, It is definitely a tool to avoid. Just take a look at whole list of suspicious activities that it initiates, meaning that intense spying on users and potential installations of additional malware can occur.

Even if you are looking for a new PDF reader, specifically designed to serve Windows 10, 8, 7, Vista and XP, please remember that this software application is extremely suspicious. In addition to this, it delivers a browser hijacked into operating systems. Some Internet visitors might download Lite PDF Reader virus accidentally via bundles of programs.

This means that people will agree to change their browsers’ preferences without their knowledge. Check whether this malicious tool has invaded your privacy and if you should remove it from Control Panel. Since this program spawns many harmful processes, it probably would be best to run a scan with Spyhunter and find all of the processes it began and the malware it additionally installed.

Always be prepared for a malware attack

If you wish to avoid stealthy installations of programs, we advise you to select advanced/custom modes during every installer. If you do, you will be able to read more information about the program you selected. For instance, you will be able to read Eula and Privacy Policy. Furthermore, you will learn about suspicious conditions.

In this case, during setup of Lite PDF Reader virus, people are informed that they have to set as their preference in order to enjoy free services. This is definitely not an action we recommend users to do. There are more appropriate programs to choose form that serve the exact same purpose. Choose an alternative from respectable developers.

How to recover Lite PDF Reader virus encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:

for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before Lite PDF Reader virus has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3

Step 2. Complete removal of Lite PDF Reader virus

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to Lite PDF Reader virus. You can check other tools here.  

Step 3. Restore Lite PDF Reader virus affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually Lite PDF Reader virus tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover Lite PDF Reader virus encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *