PCPrivacyTool

Description: Rogue Security Program
Risk Level: High
Date of First Occurence: Friday, April 25, 2008
Software Developer: (unknown)
Brief Info: Rogue/Suspect Anti-Spyware Product "Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
Removal: This threat can be removed using "Spyware Terminator"

ELIMINAR SPYWARE »

Geographical Distribution of Threat "PCPrivacyTool"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\PCPrivacyTool\plug\GDCW.exe MD5: EF8F4DF3064DC35001375120FFA3F87C Size:282624
  2. Detected Files with variable Filenames:

Detecting items list:

  1. Files by Name %APPDATA%\Microsoft\Internet Explorer\Quick Launch\PCPrivacyTool unregistered.lnk %DESKTOP%\Install PCPrivacyTool .lnk %DESKTOP%\PCPrivacyTool unregistered.lnk
  2. Files by Directories %START_PROGRAMSALL%\PCPrivacyTool %ProgramFiles%\PCPrivacyTool
  3. Files by CLSID or Name CLSID=B33DE756-DEEE-4D7A-87DB-1D905BA2AA21
  4. Registry Keys HKCU\Software\PCPrivacyTool HKCR\?\shellex\ContextMenuHandlers\secure_del HKCR\.exe\shellex\ContextMenuHandlers\secure_del HKCR\.lnk\ShellEx\ContextMenuHandlers\secure_del HKCR\Directory\Background\shellex\ContextMenuHandlers\secure_del HKCR\Directory\shellex\ContextMenuHandlers\secure_del HKCR\Drive\shellex\ContextMenuHandlers\secure_del HKCR\Folder\shellex\ContextMenuHandlers\secure_del HKCR\SystemFileAssociations\Directory.Audio\shellex\ContextMenuHandlers\secure_del HKCR\SystemFileAssociations\Directory.Image\shellex\ContextMenuHandlers\secure_del HKCR\SystemFileAssociations\Directory.Video\shellex\ContextMenuHandlers\secure_del HKCR\exefile\shellex\ContextMenuHandlers\secure_del HKCR\lnkfile\shellex\ContextMenuHandlers\secure_del HKLM\SOFTWARE\PCPrivacyTool HKLM\SOFTWARE\ugdccw
  5. Registry Values HKCU\Software\Microsoft\Windows\CurrentVersion\Run ValueName=PCPrivacyTool HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=PCPrivacyTool HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=ugdccw HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved ValueName={B33DE756-DEEE-4D7A-87DB-1D905BA2AA21}

« Go to Software Database