Windows Recovery
Windows Recovery
Found:
2011-03-23
Description:
Win32.FraudTool.WindowsRecovery is a rogue application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.
Known system changes:
Files
C:\Documents and Settings\All Users\Application Data\<random>.exe
C:\Documents and Settings\<user account>\Desktop\Windows Recovery.lnk
Folders
C:\Documents and Settings\<user account>\Start Menu\Programs\Windows Recovery
Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Random"