Home Malware Programs Potentially Unwanted Programs (PUPs) From Doc to Pdf Toolbar

From Doc to Pdf Toolbar

Posted: July 24, 2013

Threat Metric

Ranking: 60
Threat Level: 1/10
Infected PCs: 1,988,902
First Seen: July 24, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

The From Doc to Pdf Toolbar is an add-on application that may offer several quick function buttons for converting documents to a PDF file. While the From Doc to Pdf Toolbar proves to be somewhat useful for some computer users, it is considered to be a potentially unwanted program (PUP). Created by Mindspark Interactive Network, known for distributing many other toolbar applications, From Doc to Pdf Toolbar is primarily downloaded from one site that is only designed to market the From Doc to Pdf Toolbar application. Use of From Doc to Pdf Toolbar may prove to be beneficial to some computer users for the need to convert files, while to others it could be an unwanted application that is taking space on their web browser screen. If fall in the latter category, then it might be in your interest to remove the From Doc to Pdf Toolbar and get rid of the secondary side effects its installation may cause.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\FromDocToPDF_65\bar\1.bin\65brmon64.exe File name: 65brmon64.exe
Size: 71.75 KB (71752 bytes)
MD5: 51b894a86bcd09501fcbf97876126503
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FromDocToPDF_65\bar\1.bin
Group: Malware file
Last Updated: June 28, 2020

Registry Modifications

The following newly produced Registry Values are:

CLSID{017d68f2-19b3-41ae-9d8a-8b09dbd25479}{1747AE4D-0A83-4336-84D4-48500BF1554F}{1EF6208B-483A-48F6-B9E5-9B6C54200F8C}{2bd4465d-669a-42e6-b449-636b0b10ebb8}{2C9D27D8-C81E-4968-8026-E725E01650C1}{314D051A-F3B4-4B7A-AAB4-1122FB82A0B5}{316A2A46-F832-49B3-95E0-D460BD88D6B4}{36B445BF-1B84-466A-A623-A360A8CFF8C3}{3700b685-d795-4e17-9b78-73bcee5d4086}{37E2C8D2-3EF0-46D4-AD11-A8DA53942034}{3BB1BA04-1B88-4690-9AD3-0D38412F5FF1}{3e6260ac-bc6f-44b4-942b-1568c367543a}{3EFEC319-72E8-42AA-AC38-8CF8A0661CDD}{463A3C2B-3B87-4FAD-A9A6-CD1B93ED836C}{4AD8E6E4-3DFE-458D-845D-55F516C7C3B0}{4c60e5ab-5c68-4c59-abaa-885010b24b32}{4D8AEB1D-4ED4-44AC-A039-4775B2575DB0}{4ffa72ec-9fd9-4b2b-92a5-68b60885fd8a}{504b4aa9-9952-4490-b0e1-80a5321c35f7}{6191571E-F7EE-47C3-B229-2DFAC70DB5D2}{62D88F68-AC05-4FBF-AC16-E76B3B7B6531}{6467B28C-D408-4066-8B26-056335875D3D}{6CBF5C01-C876-481B-867E-111CB1D2A7D6}{72d05120-df65-4c27-921e-899b5267fef2}{74C02D12-FAEE-4834-80D2-5B7D2480AD61}{777CEBBF-A763-42BE-ABBF-FF264689666B}{840AE8AE-D547-433E-985C-6BF6C74F5084}{87509D74-1F24-4B10-A14E-0AACF713CE14}{9CB19259-5D60-49A7-8AF7-2B7CAF36C124}{9FD6C2C1-C847-410A-995A-AEE5F27F0674}{A1F3E70D-04BA-47FB-ACCA-CC8FCFA74D41}{a235e1e3-6296-4710-af39-104a7faa6c7c}{A7C6FA4E-F2A1-4D4B-90CB-2757143E7AAB}{A85ACA7E-5CD2-461B-877A-994CCCCF491C}{A9141680-DC75-4DD7-B86D-9CC2A83DCB9B}{ae84501a-2cb6-41d6-b3a7-9679bdbdfa0b}{afa196f4-80e5-47ad-b7bc-c671487d36fb}{b7fd68f7-d28b-431e-9ee8-e45d915b7f17}{bc7e25d7-4681-46a3-af5a-9a1b865783ed}{BF6FDBB8-7CD5-402D-AB4F-E4F13D3490C8}{C64B02A7-77F8-4EC9-B2C3-78EBBFFC00EE}{c66a678d-5e6c-4af9-8f57-c6192f42cf74}{C7879E06-4C3F-4061-B619-7CFD072E4F26}{cbbea4b9-b183-47ac-8b1f-fd526ac99a8d}{cd1d181e-c654-4ca5-9d09-b3648537fd7d}{CF9608AD-4ECF-4A16-B122-B374299DE7B5}{DAAD8A57-6BD6-48D0-9034-093AD607C39A}{e0c3a839-0e5e-4ebc-9f8f-e56f8fc732ce}{e1c4699e-5e74-4f30-a4a2-378e45d44f07}{E1DA9C58-A56C-4F9E-A9DD-32BCF8CCC98B}{E3CDDB72-3ADC-4920-B42B-68A8C29FA942}{E70DAE92-1A31-4AB8-9FCF-52FBDA0CC66A}{F05D47B2-7C9F-401D-A083-3AA4A4711F4F}{f236ca79-3123-4afb-9f74-e98117ad5625}{F284EDCC-94E4-4C79-8A27-D7F42BEE216C}{F39D8ED3-A6F6-427F-8AF8-BC9784FA70D8}{F4F94932-9CDB-45F4-BD4A-C77B5074D353}{FC2B119B-2352-4E7A-9197-B9E1BBADE61B}{FC65C7F9-115F-42A6-BC49-BF7A60A5314E}File name without pathdownload.fromdoctopdf[1].xmlfromdoctopdf.dl.myway[1].xmlfromdoctopdf.dl.tb.ask[1].xmlhttp_download.fromdoctopdf.com_0.localstoragehttp_download.fromdoctopdf.com_0.localstorage-journalhttp_fromdoctopdf.dl.myway.com_0.localstoragehttp_fromdoctopdf.dl.myway.com_0.localstorage-journalhttp_fromdoctopdf.dl.tb.ask.com_0.localstoragehttp_fromdoctopdf.dl.tb.ask.com_0.localstorage-journalhttp_www.fromdoctopdf.com_0.localstoragehttp_www.fromdoctopdf.com_0.localstorage-journalwww.fromdoctopdf[1].xmlHKEY..\..\..\..{RegistryKeys}SOFTWARE\FromDocToPDFSoftware\Microsoft\Internet Explorer\Approved Extensions\{A235E1E3-6296-4710-AF39-104A7FAA6C7C}Software\Microsoft\Internet Explorer\Approved Extensions\{C66A678D-5E6C-4AF9-8F57-C6192F42CF74}Software\Microsoft\Internet Explorer\Approved Extensions\{F236CA79-3123-4AFB-9F74-E98117AD5625}Software\Microsoft\Internet Explorer\DOMStorage\download.fromdoctopdf.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\fromdoctopdf.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\fromdoctopdf.dl.myway.comSoftware\Microsoft\Internet Explorer\DOMStorage\fromdoctopdf.dl.tb.ask.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.fromdoctopdf.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36b445bf-1b84-466a-a623-a360a8cff8c3}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6cbf5c01-c876-481b-867e-111cb1d2a7d6}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{701f5c41-bb30-46da-a56b-68784b0b762b}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a3b975a0-f679-444e-9d94-6d292fa53140}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e0c3a839-0e5e-4ebc-9f8f-e56f8fc732ce}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e1035f55-4c0c-4efc-9aae-38f421fce726}Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\download.fromdoctopdf.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fromdoctopdf.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.fromdoctopdf.comSOFTWARE\Microsoft\Tracing\FromDocToPDF_RASAPI32SOFTWARE\Microsoft\Tracing\FromDocToPDF_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{A235E1E3-6296-4710-AF39-104A7FAA6C7C}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C66A678D-5E6C-4AF9-8F57-C6192F42CF74}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F236CA79-3123-4AFB-9F74-E98117AD5625}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A235E1E3-6296-4710-AF39-104A7FAA6C7C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC7E25D7-4681-46A3-AF5A-9A1B865783ED}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C39D6D30-F9E1-4290-A731-C502FE173B39}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C66A678D-5E6C-4AF9-8F57-C6192F42CF74}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F236CA79-3123-4AFB-9F74-E98117AD5625}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36b445bf-1b84-466a-a623-a360a8cff8c3}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6cbf5c01-c876-481b-867e-111cb1d2a7d6}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{701f5c41-bb30-46da-a56b-68784b0b762b}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a3b975a0-f679-444e-9d94-6d292fa53140}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e0c3a839-0e5e-4ebc-9f8f-e56f8fc732ce}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e1035f55-4c0c-4efc-9aae-38f421fce726}SOFTWARE\Wow6432Node\Microsoft\Tracing\FromDocToPDF_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\FromDocToPDF_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2bd4465d-669a-42e6-b449-636b0b10ebb8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{bc7e25d7-4681-46a3-af5a-9a1b865783ed}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c39d6d30-f9e1-4290-a731-c502fe173b39}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cbbea4b9-b183-47ac-8b1f-fd526ac99a8d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e1c4699e-5e74-4f30-a4a2-378e45d44f07}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FC2B119B-2352-4E7A-9197-B9E1BBADE61B}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}FromDocToPDF_65bar Uninstall FirefoxFromDocToPDF_65bar Uninstall Internet ExplorerFromDocToPDFTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%APPDATA%\FromDocToPDF_65%LOCALAPPDATA%\FromDocToPDFTooltab%LOCALAPPDATA%\FromDocToPDF_65%PROGRAMFILES%\FromDocToPDF_65%PROGRAMFILES(x86)%\FromDocToPDF_65%USERPROFILE%\AppData\LocalLow\FromDocToPDF_65%UserProfile%\Local Settings\Application Data\FromDocToPDFTooltab
Loading...