Threat Database Trojans Fraudtool.Win32.PCDoc

Fraudtool.Win32.PCDoc

Fraudtool.Win32.PCDoc is a Windows platform Trojan that disguises itself as a legitimate anti-spyware application. Fraudtool.Win32.PCDoc may enter a system through drive-by downloads or when visiting malicious websites. Once inside a system, Fraudtool.Win32.PCDoc will launch bogus warnings, pop-ups and online scan results causing a user to go into alarm and purchase the maliciously recommended rogue security application. Fraudtool.Win32.PCDoc may also download addition computer threats onto a compromised system.

File System Details

Fraudtool.Win32.PCDoc may create the following file(s):
# File Name Detections
1. %ProgramFiles%\PC Doc Pro v5\unins000.exe
2. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro Scheduler.exe
3. %ProgramFiles%\PC Doc Pro v5\eWebClient.dll
4. %Temp%\ESW1.tmp\d_PcDocPro_Setup.exe
5. %ProgramFiles%\PC Doc Pro v5\Update.exe
6. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro Uninstaller.exe
7. %ProgramFiles%\PC Doc Pro v5\eWebControl365.dll
8. %Temp%\is-K7IMC.tmp\_isetup\_shfoldr.dll
9. %System%\drivers\dfg.sys
10. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro.exe
11. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro Cleanup.exe
12. %ProgramFiles%\PC Doc Pro v5\Eraser.exe
13. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro.ini
14. %Temp%\is-K7IMC.tmp\_isetup\_RegDLL.tmp
15. %CommonPrograms%\PC Doc Pro v5\Uninstall PC Doc Pro v5.lnk
16. %ProgramFiles%\PC Doc Pro v5\unins000.dat
17. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro.bin
18. %DesktopDir%\PC Doc Pro v5.lnk
19. %ProgramFiles%\PC Doc Pro v5\Version.dat
20. %ProgramFiles%\PC Doc Pro v5\PC Doc Pro.dat
21. %Temp%\is-JTH64.tmp\d_PcDocPro_Setup.tmp
22. %CommonPrograms%\PC Doc Pro v5\PC Doc Pro v5.lnk

Registry Details

Fraudtool.Win32.PCDoc may create the following registry entry or registry entries:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\eSellerate\Affiliates\PUB1778953386\SKU45089540276]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebSDK.365\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebResultData.365.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebResultData.365\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebPrefillData.365]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxeServer.AxeNV.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxeServer.AxeNV\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FD96BC95-A0B9-4533-B0D3-8D47E9924D34}\1.0\FLAGS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{24158A0E-DA05-4591-BA7D-D85D801E3F11}\1.0]
[HKEY_CURRENT_USER\Software\eSellerate\Affiliates\PUB1778953386\SKU45089540276]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dfg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebSDK.365.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebResultData.365.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebResultData.365\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebPrefillData.365.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebPrefillData.365\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxeServer.AxeNV]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FD96BC95-A0B9-4533-B0D3-8D47E9924D34}\1.0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FD96BC95-A0B9-4533-B0D3-8D47E9924D34}\1.0\0\win32]
[HKEY_CURRENT_USER\Software\PC Doc Pro2008]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dfg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Doc Pro]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebSDK.365\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebResultData.365]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebPrefillData.365.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eWebPrefillData.365\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxeServer.AxeNV.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxeServer.AxeNV\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FD96BC95-A0B9-4533-B0D3-8D47E9924D34}\1.0\HELPDIR]

Trending

Most Viewed

Loading...