ZeroVaccine
ZeroVaccine
Win32.FraudTool.ZeroVaccine is a rogue anti-spyware application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.
Credit: Tachikoma
Files
%System%\avSubEngine.exe
Folders
%ProgramFiles%\ZeroVaccine
RegistryEntries
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZeroVaccineMain
Key: HKEY_LOCAL_MACHINE\SOFTWARE\ZeroVaccine
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: ZeroVaccineMain
Data: "C:\Program Files\ZeroVaccine\ZeroVaccine.exe" /Scan