Windows Restore
Windows Restore
Win32.FraudTool.WindowsRestore is a rogue anti-spyware application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.
Files
%application data%\<random>.exe
All files on disk are set to be hidden
Folders
All folders on disk are set to be hidden
RegistryEntries
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
Value: DisableTaskMgr
Data: 01, 00, 00, 00
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Value: Hidden
Data: 00, 00, 00, 00