[Symptom of Infection]
Adware.PCDefence.R is installed automatically and induces to purchase for fake repair.
- It adds itself to registry for automatic execution on system boot.
<Related URL>
hxxp://pcdefence.co.kr/etc/(...)_app.htm
hxxp://(...).com/P/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...).exe
hxxp://(...).pcdefence.co.kr/bin/(...)
hxxp://(...).pcdefence.co.kr/bin/(...)
hxxp://(...).pcdefence.co.kr/bin/(...).dat
<Registry>
[Adware.PCDefence.R] creates registries like below.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\smartconnect
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Defense
HKLM\SOFTWARE\PC Defense
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Name : pcdefenceS
Value : "(Programs Folder)\PC Defense\pcdefenceU.exe"
HKCU\Software\Microsoft\Internet Explorer
Name : pcdefence_sun
Value : "1"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Name : smartconnect
Value : "(System Folder)\smartconnect.exe sgi"
<Folder>
[Adware.PCDefence.R] creates folders like below.
(All User Account Folder)\Start\Program\PC Defense
(Programs Folder)\PC Defense
<File>
[Adware.PCDefence.R] creates files like below.
(All User Account Folder)\Start\Program\PC Defense\pcdefence Delete.lnk
(All User Account Folder)\Start\Program\PC Defense\pcdefence.lnk
(All User Account Folder)\Start\Program\PC Defense\License.url
(All User Account Folder)\Start\Program\PC Defense\Webpage.url
(Programs Folder)\PC Defense\mdata.dat
(Programs Folder)\PC Defense\pcdefence.exe
(Programs Folder)\PC Defense\pcdefenceBK.exe
(Programs Folder)\PC Defense\pcdefencedm.exe
(Programs Folder)\PC Defense\pcdefenceU.exe
(Programs Folder)\PC Defense\trackingsitedata
(Programs Folder)\PC Defense\ubdata
(System Folder)\smartconnect.dat
(System Folder)\smartconnect.exe
(System Folder)\uninst_pcdefence.exe
<Notation>
- "(Programs Folder)" could be different by OS and generally this is "C:\Program Files\"
- "(All User Account Folder)" could be different by OS and generally this is "C:\Documents and Settings\(All User Account)\"
- "(Windows Folder)" could be different by OS and generally this is "C:\Windows\"
- "(System Folder)" could be different by OS and generally this is "C:\Windows\System32\".