Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

FRAUDTOOL.WINXPRECOVERY

 

 

 

Name:

FraudTool.WinXPRecovery

Added:

May 18, 2011

Type:

Fraudtool

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When FraudTool.WinXPRecovery is executed, it installs the Rogueware, Windows XP Recovery:

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

and drops the following files:

%Allusersprofile%\Application Data\random file name.exe
 
%Allusersprofile%\Application Data\random file name ( Extension less file)

%Userprofile%\Start Menu\Programs\Windows XP Recovery\Windows XP Recovery.lnk
%Userprofile%\Start Menu\Programs\Windows XP Recovery\Uninstall Windows XP Recovery.lnk

%Userprofile%\Desktop\Windows XP Recovery.lnk

It displays fake threat messages and forces users to purchase the software in order to remove the fake threats

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4