Home Malware Programs Misleading Programs DiskHelper


Posted: January 17, 2011

DiskHelper (or Disk Helper) is a fake system optimizing tool which pretends to be a registry cleaner. DiskHelper joins Hard Drive Diagnostic, HDD Scan, Win Defragmenter and Win HDD in a growing list of similar rogue programs causing havoc in cyberspace.

Symptoms of a DiskHelper attack include the home page of your PC changing due to a browser hijacking and a fake system scan running on your machine everytime you boot-up. The bogus scan will report tons of errors to mislead you into purchasing its license. Disk Helper will also urge you to purchase the full version of the rogueware.

Disk Helper is a deceitful and pretends to fix or clean a computer's registry. DiskHelper uses deceptive security alerts and bogus registry scans as a method to get computer users to purchase the full version of the rogue registry cleaner in use. Remove DiskHelper before the hackers behind this blatant scam try to pilfer your hard-earned money.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%[User_Name]DesktopDisk Helper.lnk %Documents and Settings%[User_Name]Start MenuProgramsDisk Helper
    2 %Documents and Settings%[User_Name]Start MenuProgramsDisk HelperDisk Helper.lnk %Documents and Settings%[User_Name]Start MenuProgramsDisk HelperUninstall Disk Helper.lnk
    3 %Temp%[random characters]
    4 %Temp%[random characters].dll
    5 %Temp%[random characters].exe
    6 %Temp%dfrg
    7 %Temp%dfrgr

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[random characters]"HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[random characters].exe"

Additional Information on DiskHelper

  • The following messages's were detected:
    # Message
    1 Critical Error!
    Windows was unable to save all the data for the file [random name]. The data has been lost. This error may be caused by a failure of your computer hardware.