SpecialGuard
SpecialGuard
Win32.FraudTool.SpecialGuard is a rogue anti-spyware application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.
Credit: Tachikoma
Files
Folders
%ProgramFiles%\specialguard
%StartMenu%\specialguard
RegistryEntries
Key: HKEY_CURRENT_USER\Software\EGN
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\specialguard
Key: HKEY_LOCAL_MACHINE\SOFTWARE\specialguard
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: specialguardstart.exe
Data: C:\Program Files\specialguard\specialguardstart.exe