GoodMemory
GoodMemory
Win32.FraudTool.GoodMemory is a rogue diagnostic application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.
Credit: Tachikoma
Files
%Desktop%\Good Memory.lnk
Folders
%StartMenu%\Good Memory
RegistryEntries
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: H35fMjwiKc
Data: C:\Documents and Settings\All Users\Application Data\H35fMjwiKc.exe
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: sMucQTngLLRteNH.exe
Data: C:\Documents and Settings\All Users\Application Data\sMucQTngLLRteNH.exe