Analysis by: Kyra-Melody Gonzales

ALIASES:

a variant of Win32/Jawego.B potentially unwanted application (NOD32), Hoax.Win32.DeceptPCClean.cn (KASPERSKY), Riskware/Jawego (FORTINET)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Potentially Unwanted Application

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 5,351,920 bytes
File Type: EXE
Initial Samples Received Date: 26 Jan 2019

Arrival Details

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Potentially Unwanted Application adds the following folders:

  • %Program Files%\PC Protector Plus
  • %ProgramData%\Jawego\PC Protector Plus
  • %Common Programs%\PC Protector Plus
  • %Application Data%\Jawego\PC Protector Plus
  • %AppDataLocal%\Jawego\PC Protector Plus

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %ProgramData% is a version of the Program Files folder where any user on a multi-user computer can make changes to programs. This contains application data for all users. This is usually C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit), or C:\Documents and Settings\All Users on Windows Server 2003(32-bit), 2000(32-bit) and XP.. %Common Programs% is the folder that contains common program groups for all users, which is usually C:\Documents and Settings\All Users\Start Menu\Programs on Windows 2000, XP, and Server 2003, or C:\ProgramData\Microsoft\Windows\Start Menu\Programs on Windows Vista, 7, and 8.. %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It adds the following processes:

  • %System%\taskkill.exe /f /im "PCProtectorPlus.exe"
  • %System%\taskkill.exe /f /im "appmanager.exe"
  • %System%\taskkill.exe /f /im "BrowserCleaner.exe"
  • %System%\schtasks.exe /delete /tn "pc protector plus_startup" /f
  • %System%\schtasks.exe /delete /tn "pc protector plus_runoncehrs" /f
  • %System%\schtasks.exe /delete /tn "pc protector plus" /f
  • %System%\regsvr32.exe /s "%AppDataLocal%\Jawego\PC Protector Plus\pcpluscontexthelper32.dll"
  • %Program Files%\PC Protector Plus\PCProtectorPlus.exe -firstinstall

(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Other System Modifications

This Potentially Unwanted Application deletes the following files:

  • %Application Data%\Jawego\PC Protector Plus\Settings.db-journal

(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Dropping Routine

This Potentially Unwanted Application drops the following files:

  • %Program Files%\PC Protector Plus\is-49ULT.tmp
  • %Program Files%\PC Protector Plus\clamunpack\is-LPLAL.tmp
  • %ProgramData%\Jawego\PC Protector Plus\is-4BGKI.tmp
  • %AppDataLocal%\Jawego\PC Protector Plus\is-D4NSK.tmp
  • %Common Programs%\PC Protector Plus\PC Protector Plus.lnk
  • %Common Programs%\PC Protector Plus\Register PC Protector Plus.lnk
  • %Common Programs%\PC Protector Plus\Uninstall PC Protector Plus.lnk
  • %Public%\Desktop\PC Protector Plus.lnk
  • %Application Data%\Jawego\PC Protector Plus\Settings.db
  • %Application Data%\Jawego\PC Protector Plus\Settings.db-journal
  • %Application Data%\Jawego\PC Protector Plus\PCPLog.txt
  • %Application Data%\PCPRJ\backup6.bin
  • %Application Data%\Jawego\PC Protector Plus\QDetail.db
  • %Application Data%\Jawego\PC Protector Plus\QDetail.db-journal

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %ProgramData% is a version of the Program Files folder where any user on a multi-user computer can make changes to programs. This contains application data for all users. This is usually C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit), or C:\Documents and Settings\All Users on Windows Server 2003(32-bit), 2000(32-bit) and XP.. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Common Programs% is the folder that contains common program groups for all users, which is usually C:\Documents and Settings\All Users\Start Menu\Programs on Windows 2000, XP, and Server 2003, or C:\ProgramData\Microsoft\Windows\Start Menu\Programs on Windows Vista, 7, and 8.. %Public% is the folder that serves as a repository of files or folders common to all users, which is usually C:\Users\Public in Windows Vista, 7, and 8.. %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Other Details

This Potentially Unwanted Application adds the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
TELNO = ({BLOCKED}) {BLOCKED} - {BLOCKED}

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
TELNOFR = {BLOCKED}.{BLOCKED}.54.27.59

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
TELNODE = ({BLOCKED}) {BLOCKED} - {BLOCKED}

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
isphone = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
issilent = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
showpb = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
showfth = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
showfthsetting = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
showsm = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
showbc = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
IsScanOptional = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
NoLPHIconNeeded = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
Params
utm_source = p9jwsite

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
Params
utm_campaign = p9jwdefault

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
Params
utm_medium = newbuild

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
utm_source = p9jwsite

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
utm_campaign = p9jwdefault

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
utm_medium = newbuild

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
affiliateid =

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
x-at =

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
utm_source = p9jwsite

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
utm_campaign = p9jwdefault

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
utm_medium = newbuild

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
affiliateid =

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
x-at =

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
TELNO = ({BLOCKED}) {BLOCKED}-{BLOCKED}

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
TELNOFR = {BLOCKED}.{BLOCKED}.54.27.59

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus value: data:
TELNODE = ({BLOCKED}) {BLOCKED}-{BLOCKED}

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
BuyNowURL = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
BuyNowURLPDU = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
BuyNowURLPCPS = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
BuyNowURLPCP = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
BuyNowURLPB = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURLPDU = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURLPCPS = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURLPCP = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURLPB = http://www.{BLOCKED}ectorplus.com/buynow/?

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
InstalledPath = %Program Files%\PC Protector Plus

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
InstalledPath = %Program Files%\PC Protector Plus

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
SOFTWARE\Microsoft\Windows\
CurrentVersion\Shell Extensions\Approved
{63F58340-0CD0-403B-B6E8-4E1449F01C6F} = Scan with PC Protector Plus

HKEY_CURRENT_USER\Software\Jawego\
params
PCPP = 1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
Params
PCPP = 1

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus\LANG
LangCode = en

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus\LANG
LangCode = en

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus\LANG
LangID = 0

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus\LANG
LangID = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
afterInstallUrl = http://{BLOCKED}ectorplus.com/afterinstall/?utm_content=AfterInstall&utm_term=Setup&page=install&

HKEY_CURRENT_USER\Software\PCPRJ\
antimalware\key\6

HKEY_LOCAL_MACHINE\SOFTWARE\PCPRJ\
antimalware\key\6

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
Key =

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
Expired = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
REGVER = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
REGVER-UNINSTALL = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
MaxFixLimit = 0

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
Key =

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
Expired = 0

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
REGVER = 0

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
REGVER-UNINSTALL = 0

HKEY_CURRENT_USER\Software\Jawego\
PC Protector Plus
MaxFixLimit = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
EnableFileTracing = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
EnableConsoleTracing = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
FileTracingMask = 4294901760

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
ConsoleTracingMask = 4294901760

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
MaxFileSize = 1048576

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASAPI32
FileDirectory = %windir%\tracing

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
EnableFileTracing = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
EnableConsoleTracing = 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
FileTracingMask = 4294901760

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
ConsoleTracingMask = 4294901760

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
MaxFileSize = 1048576

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Tracing\PCProtectorPlus_RASMANCS
FileDirectory = %windir%\tracing

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Unknown\shell\openas\
command

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Unknown\shell\openas\
command
PC Protector Plus.bak = %System%\rundll32.exe %System%\shell32.dll,OpenAs_RunDLL %1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Unknown\shell\opendlg\
command

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Unknown\shell\opendlg\
command
PC Protector Plus.bak = %System%\rundll32.exe %System%\shell32.dll,OpenAs_RunDLL %1

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

HKEY_LOCAL_MACHINE\SOFTWARE\Jawego\
PC Protector Plus
RenewNowURL = http://www.{BLOCKED}ectorplus.com/renewal/?

It connects to the following possibly malicious URL:

  • www.{BLOCKED}ectorplus.com