DiskOK

DiskOK

Found: 
2011-01-11
Description: 

Win32.FraudTool.DiskOK is a rogue anti-spyware application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.

 

Credit: Tachikoma

Known system changes: 

Files

Folders

%StartMenu%\Disk OK

RegistryEntries

Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: GXADAOEbUaHOS.exe
Data: C:\Documents and Settings\All Users\Application Data\GXADAOEbUaHOS.exe
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: ViTo9PqF8Z3sct
Data: C:\Documents and Settings\All Users\Application Data\ViTo9PqF8Z3sct.exe