Pconguard.com

Pconguard.com is a deceptive domain that is involved in the distribution of Virus Protector. Pconguard.com, also known as Pconguard.net, is typically placed into users' Hosts files by browser hijacking Trojans. Once a user is redirected to Pconguard.com a fake system scan will be conducted and it will report that it detected several malicious parasites on the PC. Fake security alerts and pop-up messages will also be displayed in order to scare the user into purchasing Virus Protector, which is purportedly the only remedy for the PC. Do not believe the security messages displayed on Pconguard.com and never purchase anything on the website.

File System Details

Pconguard.com may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
2. %Program Files%\Internet Explorer\[random].dll
3. %WINDOWS%\system32\[random].exe
4. %WINDOWS%\system32\drivers\[random].dll
5. %Documents and Settings%\[UserName]\Application Data\[random].dll
6. %Program Files%\Internet Explorer\[random].exe
7. %WINDOWS%\[random].dll
8. %WINDOWS%\system32\drivers\[random].exe
9. %Documents and Settings%\[UserName]\Application Data\[random].exe
10. %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
11. %WINDOWS%\[random].exe
12. %WINDOWS%\system32\[random].dll

Registry Details

Pconguard.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "[random].dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"

Trending

Most Viewed

Loading...