Home Customer Support Solutions PCTechHotline

PCTechHotline

Posted: February 25, 2014

Threat Metric

Ranking: 10,002
Threat Level: 1/10
Infected PCs: 2,150
First Seen: February 25, 2014
Last Seen: October 10, 2023
OS(es) Affected: Windows


PC Tech Hotline is a potentially unwanted program (PUP) produced by Crawler. After installation and setup, PC Tech Hotline may define a registry entry which allows it to be launched automatically on every Windows boot-up for all user logins. PC Tech Hotline may add a background controller service that is set to automatically start. Delaying the start of this service may be possible through the service manager. PC users may order the service by submitting a service plan order through the PC Tech Hotline website or by calling PC Tech Hotline. Once PC Tech Hotline accepts the service plan order submitted by the computer user, then he may receive an email from PC Tech Hotline at the email address that he provides or has provided to PC Tech Hotline as a part of the registration process for the service. PC Tech Hotline is not responsible for rendering services in relation with any service plan order that it has not accepted. Once installed, PCTechHotline may start with the computer system even after changing start-up settings in its settings window. PCTechHotline may spread and access the computer through other bundled freeware.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\PCTechHotline\PCTHHook.exe File name: PCTHHook.exe
Size: 64.36 KB (64360 bytes)
MD5: f9848829e5e3be02dda0fd3385de39fc
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PCTechHotline
Group: Malware file
Last Updated: March 17, 2014
%PROGRAMFILES(x86)%\PCTechHotline\PCTHHook64.exe File name: PCTHHook64.exe
Size: 74.08 KB (74088 bytes)
MD5: c9d591eb47ba25de05f647b0fe229976
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PCTechHotline
Group: Malware file
Last Updated: March 17, 2014
C:\Program Files\pctechhotline\PCTHdesk.64.dll File name: C:\Program Files\pctechhotline\PCTHdesk.64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\pctechhotline\PCTHdesk.dll File name: C:\Program Files\pctechhotline\PCTHdesk.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\pctechhotline\PCTHHook.dll File name: C:\Program Files\pctechhotline\PCTHHook.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\pctechhotline\PCTHHook64.dll File name: C:\Program Files\pctechhotline\PCTHHook64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\pctechhotline\unins000.exe File name: C:\Program Files\pctechhotline\unins000.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{6E30A318-C2A8-4874-9C44-30EB821658BA}File name without pathPC Tech Hotline.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PCTechHotlineSoftware\PCTechHotlineSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\PCTechHotlineSOFTWARE\Wow6432Node\PCTechHotlineSYSTEM\ControlSet001\services\PCTechHotlineSvcSYSTEM\ControlSet002\services\PCTechHotlineSvcSYSTEM\CurrentControlSet\services\PCTechHotlineSvcHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{A0B0DA25-DD15-4739-92A3-62D3424F043A}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\PC Tech Hotline%ALLUSERSPROFILE%\Start Menu\Programs\PC Tech Hotline%APPDATA%\PC Tech Hotline%PROGRAMFILES%\PCTechHotline%PROGRAMFILES(x86)%\PCTechHotline
The following URL's were detected:
pctechhotline.com
Loading...