Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Rogues - PCPrivacyTool family

Currently, there are 30 variants (that I know) of the rogue privacy program known as PCPrivacyTool. They give exaggerated warnings and label legitimate programs as privacy risks in order to goad the user into buying a full license for the application to fix these errors. The applications can be manually downloaded and installed, or if your system is vulnerable (without current, adequate protection), they may be installed by a downloader - without the user's consent.

Please note that throughout this page I only refer to the HijackThis (or HJT) startup entries and not all associated files - to keep in with the theme of the rest of the site. Note that if you have more than one rogue installed that uses a file common to other rogues the HJT log entry (and maybe filename) could have a pair of () with number inside appended, i.e., HKLM\..\Run: [Salestart(1)]. See here for an example of such a log.

PCPrivacyTool

The following image (© Symantec) shows the main screen for PCPrivacyTool (click on the image for a larger version - applies throughout):

PcPrivacyTool

HijackThis (or HJT) log startup entries identified:

The one file they all share (although a different version in each case obviously) is GDC.exe. Many of the others are also shared between the variants - but not necessarily always the same one, as you'll see below. In addition, the entries above are from a number of different logs - presumably from different versions of the rogue.

Other registry entries identified:

External links:

Any removal guide referred to below uses MalwareBytes Anti-Malware, which incorporates the functionality from their popular (but now discontinued) RogueRemover products:

MalwareBytes

Variants

Before dealing with the individual variants, here are some screenshots from some of them (© BleepingComputer) showing the common user interface:

ContentEraser FilterProgram PrivacyConductor SecurePCCleaner WinAnonymous YourPrivacyGuard

Index

ConducteurPrive MenaceFighter OczyszczaczKomputerza SchijfControleur
ConfidentSurf MistikotitaTuIpologisti OnlineHelpmate SecurePCCleaner
ContentEraser MonContenuassistant PC Drive Tool SuspenzorPC
DefenseNetSurfage MyContentAssistant PrivacyConductor TemizSurucu
DriveDefender Nettordinateur PrivacyWarrior TurvaPC
FestplattenReiniger NetSurfageAssure ProtectionDeDriver WinAnonymous
FilterProgram NettoyeurDePC SanitarDiska YourPrivacyGuard
HistoriaLout. NoCompromaat    

ConducteurPrive

(French → "Private Driver")

HJT log entries:

ConfidentSurf

HJT log entries:

ContentEraser

HJT log entries:

External links:

DefenseNetSurfage

HJT log entries:

DriveDefender

HJT log entries:

FestplattenReiniger

(German → "Disk Cleaner")

HJT log entries:

Other registry entries:

FilterProgram

HJT log entries:

Other registry entries:

External links:

HistoriaLout.

HJT log entries:

MenaceFighter

HJT log entries:

MistikotitaTuIpologisti

(Greek)

HJT log entries:

Other registry entries:

MonContenuassistant

HJT log entries:

MyContentAssistant

HJT log entries:

Nettordinateur

(French → "Nett PC")

HJT log entries:

NetSurfageAssure

HJT log entries:

NettoyeurDePC

HJT log entries:

NoCompromaat

(Dutch)

HJT log entries:

Other registry entries:

OczyszczaczKomputerza

(Polish → "Computer Cleaner")

HJT log entries:

Other registry entries:

OnlineHelpmate

HJT log entries:

External links:

PC Drive Tool

HJT log entries:

Other registry entries:

PrivacyConductor

HJT log entries:

External links:

PrivacyWarrior

Registry entries:

External links:

ProtectionDeDriver

(French)

HJT log entries:

SanitarDiska

(Romanian → "Disk Health")

Registry entries:

Other registry entries:

SchijfControleur

(Dutch → "Disk Controller")

HJT log entries:

SecurePCCleaner

HJT log entries:

External links:

SuspenzorPC

(Czech)

HJT log entries:

Other registry entries:

TemizSurucu

(Turkish → "Clean Driver")

Registry entries:

TurvaPC

(Finnish → "SecurityPC")

HJT log entries:

WinAnonymous

HJT log entries:

External links:

YourPrivacyGuard

HJT log entries:

External links:

Back to Rogues - Overview

Copyright © Pacman's Portal, 2001 - 2017
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home