Analysis by: Mariefher Grace Villanueva

ALIASES:

Trojan-Spy.Agent (IKARUS)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Potentially Unwanted Application

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 2,174,544 bytes
File Type: EXE
Initial Samples Received Date: 13 Apr 2026

Arrival Details

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Potentially Unwanted Application drops the following files:

  • %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe → downloaded second-stage Inno Setup launcher
  • %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe.xml → installer state XML
  • %User Temp%\pdfeditor_ts\galog.json → Google Analytics telemetry log
  • %User Temp%\pdfeditor_ts\pdfeditor_ts_.log → downloader runtime log
  • %User Temp%\Tenorshare PDNob_Setup_.log → Inno Setup install log
  • %User Temp%\Ext.dll → backup copy of the shell-extension DLL
  • %User Temp%\findSoftRes.txt → output of tasklist | find running-process check
  • %AppDataLocalLow%\Microsoft\CryptnetUrlCache\Content\* → Authenticode CRL cache entry
  • %AppDataLocalLow%\Microsoft\CryptnetUrlCache\MetaData\* → Authenticode CRL cache metadata
  • Component files inside "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\"
  • %Public%\Desktop\Tenorshare PDNob.lnk → all-users desktop shortcut
  • %Common Programs%\Microsoft\Windows\Start Menu\Programs\Tenorshare PDNob.lnk → Start Menu launcher
  • %Common Programs%\Microsoft\Windows\Start Menu\Programs\(Default)\Uninstall Tenorshare PDNob.lnk → Start Menu uninstaller shortcut

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocalLow% is the LocalLow Application Data folder, which is usually C:\Users\{user name}\AppData\LocalLow on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Public% is the folder that serves as a repository of files or folders common to all users, which is usually C:\Users\Public in Windows Vista, 7, and 8.. %Common Programs% is the folder that contains common program groups for all users, which is usually C:\Documents and Settings\All Users\Start Menu\Programs on Windows 2000, XP, and Server 2003, or C:\ProgramData\Microsoft\Windows\Start Menu\Programs on Windows Vista, 7, and 8.)

It adds the following processes:

  • pdfeditor_ts_1.0.0.0.exe /VERYSILENT /SP/NORESTART /DIR="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\" /LANG=en /LOG="%User Temp%\Tenorshare PDNob_Setup_20260210224906.log" /sptrack null → Inno Setup launcher (spawned by the PUA itself)
  • "%System%\explorer.exe" /e, "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe" → launches the installed application (spawned by the PUA itself)
  • "%User Temp%\is-L0C59.tmp\pdfeditor_ts_1.0.0.0.tmp" /SL5="$2309A6,191176036,234496,%User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe" /VERYSILENT /SP/NORESTART /DIR="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\" /LANG=en /LOG="%User Temp%\Tenorshare PDNob_Setup_20260210224906.log" /sptrack null → Inno Setup extracted install worker (spawned by pdfeditor_ts_1.0.0.0.exe)
  • "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd" /c rmdir /q /s "%Program Files%\PDNobLink" 2>nul (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd" /c mklink /D "%Program Files%\PDNobLink" "%Program Files% (x86)\Tenorshare\Tenorshare PDNob" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Default.exe" .pdf .Menu.EXE (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • %System%\cmd.exe /c ie4uinit.exe -ClearIconCache (spawned by Default.exe) (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • ie4uinit.exe -ClearIconCache (spawned by the cmd.exe above)
  • %System%\RunDll32.exe %System%\migration\WininetPlugin.dll,MigrateCacheForUser /m /0 (spawned by ie4uinit.exe)
  • %System%\RunDll32.exe %System%\migration\WininetPlugin.dll,MigrateCacheForUser /m /0 (spawned by ie4uinit.exe)
  • %System%\cmd.exe /c ie4uinit.exe -show (spawned by Default.exe)
  • ie4uinit.exe -show (spawned by the cmd.exe above)
  • "cmd.exe" /C mkdir "%AppDataLocal%\PDNob PDF Editor" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd.exe" /C copy /Y "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" "%AppDataLocal%\PDNob PDF Editor\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd.exe" /C copy /Y "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" "%User Temp%\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd.exe" /C del /Q "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • regsvr32.exe /s "%AppDataLocal%\PDNob PDF Editor\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • "cmd.exe" /C reg add "HKEY_CLASSES_ROOT\Applications\Recorder.exe" /v NoStartPage /t REG_NONE /f (spawned by pdfeditor_ts_1.0.0.0.tmp)
  • reg add "HKEY_CLASSES_ROOT\Applications\Recorder.exe" /v NoStartPage /t REG_NONE /f (reg.exe spawned by the cmd.exe above)
  • "%System%\netsh.exe" advfirewall firewall add rule name="PDNob PDF Editor.exe" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe.exe" dir=in action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="PDNob PDF Editor.exe" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe.exe" dir=out action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="Recorder" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\Recorder.exe" dir=in action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="Recorder" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\Recorder.exe" dir=out action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="EETime" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\EETime.exe" dir=in action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="EETime" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\EETime.exe" dir=out action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="PdnobShot" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\PdnobShot.exe" dir=in action=allow enable=yes (firewall rule addition)
  • "%System%\netsh.exe" advfirewall firewall add rule name="PdnobShot" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\PdnobShot.exe" dir=out action=allow enable=yes (firewall rule addition)

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It creates the following folders:

  • %User Temp%\pdfeditor_ts\ → downloader working directory
  • %User Temp%\is-.tmp\ → Inno Setup extraction directory
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\ → application install directory (~1,980 files installed)
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\Uninstall\ → custom uninstaller subdirectory
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\GuuGrab\ → screen-grab plugin
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\ → screenshot plugin
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\ → OBS-based screen recorder plugin
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\convent\Win\Windows\ → document converter helper
  • %AppDataLocal%\PDNob PDF Editor\ → per-user app data hosting the registered shell extension

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Other Details

This Potentially Unwanted Application adds the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
Tenorshare\Downloader2.5.0

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
GuidGuidold

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{Tenorshare PDNob}_is1

HKEY_CLASSES_ROOT\PDNob PDF Editor.Menu.EXE

HKEY_CLASSES_ROOT\SystemFileAssociations\.pdf\
shell\PDNob PDF Editor.Menu.EXE

HKEY_CURRENT_USER\Software\Classes\
.pdf\OpenWithProgids\PDNob PDF Editor.Menu.EXE

It connects to the following possibly malicious URL:

  • http://www.{BLOCKED}hare.com/downloads/service/softwarelog.txt (resolved to {BLOCKED}.{BLOCKED}.105.9:80) → vendor telemetry / update check
  • {BLOCKED}.{BLOCKED}.24.249:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (primary)
  • {BLOCKED}.{BLOCKED}.2.37:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (secondary)
  • {BLOCKED}.{BLOCKED}.3.37:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (secondary)
  • a23-11-39-161.deploy.static.{BLOCKED}technologies.com:80 → Authenticode CRL/OCSP for signature validation

  SOLUTION

Minimum Scan Engine: 9.800
SSAPI PATTERN File: 2.933.00
SSAPI PATTERN Date: 09 Apr 2026

Step 1

Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.

Step 2

Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.

Step 3

Remove PUA.Win32.PDNob.A by using its own Uninstall option

[ Learn More ]
To uninstall the grayware process

Step 4

Delete this registry key

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\
    • Downloader2.5.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
    • GuidGuidold
  • In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\
    • {Tenorshare PDNob}_is1
  • In HKEY_CLASSES_ROOT\
    • PDNob PDF Editor.Menu.EXE
  • In HKEY_CLASSES_ROOT\SystemFileAssociations\.pdf\shell\
    • PDNob PDF Editor.Menu.EXE
  • In HKEY_CURRENT_USER\Software\Classes\.pdf\OpenWithProgids\
    • PDNob PDF Editor.Menu.EXE

Step 5

Search and delete this file

[ Learn More ]
There may be some files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.  
  • %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe
  • %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe.xml
  • %User Temp%\pdfeditor_ts\galog.json
  • %User Temp%\pdfeditor_ts\pdfeditor_ts_.log
  • %User Temp%\Tenorshare PDNob_Setup_.log
  • %User Temp%\Ext.dll
  • %User Temp%\findSoftRes.txt
  • %Public%\Desktop\Tenorshare PDNob.lnk
  • %Common Programs%\Microsoft\Windows\Start Menu\Programs\Tenorshare PDNob.lnk
  • %Common Programs%\Microsoft\Windows\Start Menu\Programs\(Default)\Uninstall Tenorshare PDNob.lnk

Step 6

Search and delete these folders

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
  • %User Temp%\pdfeditor_ts\
  • %User Temp%\is-.tmp\
  • %Program Files% (x86)\Tenorshare\Tenorshare PDNob\
  • %AppDataLocal%\PDNob PDF Editor\

Step 7

Scan your computer with your Trend Micro product to delete files detected as PUA.Win32.PDNob.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:


Did this description help? Tell us how we did.