Home Malware Programs Browser Hijackers Pconguard.com

Pconguard.com

Posted: April 22, 2010

Pconguard.com (or Pconguard.net) is a misleading Internet domain promoting Virus Protector fake anti-spyware. Pconguard.com is designed to redirect computer users to a corrupt website which appears to be a system scan page. It will scan your PC for free and display infections that do not exist. Then you will be bombarded by popup warnings urging the purchase of Virus Protector. Do not become another hapless victim of cyber-crime and have all threats related to Virus Protector and Pconguard removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Application Data\[random].dll
    2 %Documents and Settings%\[UserName]\Application Data\[random].exe
    3 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
    4 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
    5 %Program Files%\Internet Explorer\[random].dll
    6 %Program Files%\Internet Explorer\[random].exe
    7 %WINDOWS%\[random].dll
    8 %WINDOWS%\[random].exe
    9 %WINDOWS%\system32\[random].dll
    10 %WINDOWS%\system32\[random].exe
    11 %WINDOWS%\system32\drivers\[random].dll
    12 %WINDOWS%\system32\drivers\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "[random].dll"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
Loading...