NetBoan

NetBoan

Found: 
2011-03-03
Description: 

Win32.FraudTool.NetBoan is a rogue anti-spyware application. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats.

Known system changes: 

Files

Folders

%ProgramFiles%\Netboan

RegistryEntries

Key: HKEY_LOCAL_MACHINE\SOFTWARE\HKFNetboan
Key: HKEY_LOCAL_MACHINE\SOFTWARE\SKNetboanLic
Key: HKEY_CLASSES_ROOT\CLSID\{32C3D0DD-0B02-4028-B080-B8A6BEFDB7CB}
Key: HKEY_CLASSES_ROOT\CLSID\{7167F147-8057-4774-89B7-E5D8DD1FDA9B}
Key: HKEY_CLASSES_ROOT\CLSID\{D78FB399-EBC5-4535-BC50-9AE8DD64F666}
Key: HKEY_CLASSES_ROOT\CLSID\{DAC288FD-691E-4B00-81E5-324DF8C8F342}
Key: HKEY_CLASSES_ROOT\Interface\{26D501B9-DF64-4B23-B41A-D8A876E75FE9}
Key: HKEY_CLASSES_ROOT\Interface\{63285D2D-9A5F-4BC4-BB1E-5E04BF634B9C}
Key: HKEY_CLASSES_ROOT\Interface\{6EB58B04-494E-4419-B8AE-CDD69CFCED23}
Key: HKEY_CLASSES_ROOT\Interface\{ECD434DB-F9CC-44FC-AA4E-A961C87413A0}
Key: HKEY_CLASSES_ROOT\NETBOANCH.NetboanCHCtrl.1
Key: HKEY_CLASSES_ROOT\NETBOANLOAD.NetboanLoadCtrl.1
Key: HKEY_CLASSES_ROOT\TypeLib\{2D641056-0FF1-4368-B85D-7291D149CD3E}
Key: HKEY_CLASSES_ROOT\TypeLib\{67A5B901-9516-4C2A-87D4-C6A3D7EBEC94}