PUA.Win32.PDNob.A
Trojan-Spy.Agent (IKARUS)
Windows


Threat Type: Potentially Unwanted Application
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Potentially Unwanted Application drops the following files:
- %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe → downloaded second-stage Inno Setup launcher
- %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe.xml → installer state XML
- %User Temp%\pdfeditor_ts\galog.json → Google Analytics telemetry log
- %User Temp%\pdfeditor_ts\pdfeditor_ts_.log → downloader runtime log
- %User Temp%\Tenorshare PDNob_Setup_.log → Inno Setup install log
- %User Temp%\Ext.dll → backup copy of the shell-extension DLL
- %User Temp%\findSoftRes.txt → output of tasklist | find running-process check
- %AppDataLocalLow%\Microsoft\CryptnetUrlCache\Content\* → Authenticode CRL cache entry
- %AppDataLocalLow%\Microsoft\CryptnetUrlCache\MetaData\* → Authenticode CRL cache metadata
- Component files inside "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\"
- %Public%\Desktop\Tenorshare PDNob.lnk → all-users desktop shortcut
- %Common Programs%\Microsoft\Windows\Start Menu\Programs\Tenorshare PDNob.lnk → Start Menu launcher
- %Common Programs%\Microsoft\Windows\Start Menu\Programs\(Default)\Uninstall Tenorshare PDNob.lnk → Start Menu uninstaller shortcut
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocalLow% is the LocalLow Application Data folder, which is usually C:\Users\{user name}\AppData\LocalLow on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Public% is the folder that serves as a repository of files or folders common to all users, which is usually C:\Users\Public in Windows Vista, 7, and 8.. %Common Programs% is the folder that contains common program groups for all users, which is usually C:\Documents and Settings\All Users\Start Menu\Programs on Windows 2000, XP, and Server 2003, or C:\ProgramData\Microsoft\Windows\Start Menu\Programs on Windows Vista, 7, and 8.)
It adds the following processes:
- pdfeditor_ts_1.0.0.0.exe /VERYSILENT /SP/NORESTART /DIR="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\" /LANG=en /LOG="%User Temp%\Tenorshare PDNob_Setup_20260210224906.log" /sptrack null → Inno Setup launcher (spawned by the PUA itself)
- "%System%\explorer.exe" /e, "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe" → launches the installed application (spawned by the PUA itself)
- "%User Temp%\is-L0C59.tmp\pdfeditor_ts_1.0.0.0.tmp" /SL5="$2309A6,191176036,234496,%User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe" /VERYSILENT /SP/NORESTART /DIR="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\" /LANG=en /LOG="%User Temp%\Tenorshare PDNob_Setup_20260210224906.log" /sptrack null → Inno Setup extracted install worker (spawned by pdfeditor_ts_1.0.0.0.exe)
- "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "%System%\cmd.exe" /c tasklist /fo csv | find /c /i "PDNob PDF Editor.exe" > "%User Temp%\findSoftRes.txt" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd" /c rmdir /q /s "%Program Files%\PDNobLink" 2>nul (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd" /c mklink /D "%Program Files%\PDNobLink" "%Program Files% (x86)\Tenorshare\Tenorshare PDNob" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Default.exe" .pdf .Menu.EXE (spawned by pdfeditor_ts_1.0.0.0.tmp)
- %System%\cmd.exe /c ie4uinit.exe -ClearIconCache (spawned by Default.exe) (spawned by pdfeditor_ts_1.0.0.0.tmp)
- ie4uinit.exe -ClearIconCache (spawned by the cmd.exe above)
- %System%\RunDll32.exe %System%\migration\WininetPlugin.dll,MigrateCacheForUser /m /0 (spawned by ie4uinit.exe)
- %System%\RunDll32.exe %System%\migration\WininetPlugin.dll,MigrateCacheForUser /m /0 (spawned by ie4uinit.exe)
- %System%\cmd.exe /c ie4uinit.exe -show (spawned by Default.exe)
- ie4uinit.exe -show (spawned by the cmd.exe above)
- "cmd.exe" /C mkdir "%AppDataLocal%\PDNob PDF Editor" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd.exe" /C copy /Y "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" "%AppDataLocal%\PDNob PDF Editor\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd.exe" /C copy /Y "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" "%User Temp%\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd.exe" /C del /Q "%Program Files% (x86)\Tenorshare\Tenorshare PDNob\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- regsvr32.exe /s "%AppDataLocal%\PDNob PDF Editor\Ext.dll" (spawned by pdfeditor_ts_1.0.0.0.tmp)
- "cmd.exe" /C reg add "HKEY_CLASSES_ROOT\Applications\Recorder.exe" /v NoStartPage /t REG_NONE /f (spawned by pdfeditor_ts_1.0.0.0.tmp)
- reg add "HKEY_CLASSES_ROOT\Applications\Recorder.exe" /v NoStartPage /t REG_NONE /f (reg.exe spawned by the cmd.exe above)
- "%System%\netsh.exe" advfirewall firewall add rule name="PDNob PDF Editor.exe" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe.exe" dir=in action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="PDNob PDF Editor.exe" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\PDNob PDF Editor.exe.exe" dir=out action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="Recorder" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\Recorder.exe" dir=in action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="Recorder" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\Recorder.exe" dir=out action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="EETime" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\EETime.exe" dir=in action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="EETime" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\bin\64bit\EETime.exe" dir=out action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="PdnobShot" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\PdnobShot.exe" dir=in action=allow enable=yes (firewall rule addition)
- "%System%\netsh.exe" advfirewall firewall add rule name="PdnobShot" program="%Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\PdnobShot.exe" dir=out action=allow enable=yes (firewall rule addition)
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
It creates the following folders:
- %User Temp%\pdfeditor_ts\ → downloader working directory
- %User Temp%\is-
.tmp\ → Inno Setup extraction directory - %Program Files% (x86)\Tenorshare\Tenorshare PDNob\ → application install directory (~1,980 files installed)
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\Uninstall\ → custom uninstaller subdirectory
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\GuuGrab\ → screen-grab plugin
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\PdnobShot\ → screenshot plugin
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\Recorder\ → OBS-based screen recorder plugin
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\plugin\convent\Win\Windows\ → document converter helper
- %AppDataLocal%\PDNob PDF Editor\ → per-user app data hosting the registered shell extension
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
Other Details
This Potentially Unwanted Application adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
Tenorshare\Downloader2.5.0
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
GuidGuidold
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\{Tenorshare PDNob}_is1
HKEY_CLASSES_ROOT\PDNob PDF Editor.Menu.EXE
HKEY_CLASSES_ROOT\SystemFileAssociations\.pdf\
shell\PDNob PDF Editor.Menu.EXE
HKEY_CURRENT_USER\Software\Classes\
.pdf\OpenWithProgids\PDNob PDF Editor.Menu.EXE
It connects to the following possibly malicious URL:
- http://www.{BLOCKED}hare.com/downloads/service/softwarelog.txt (resolved to {BLOCKED}.{BLOCKED}.105.9:80) → vendor telemetry / update check
- {BLOCKED}.{BLOCKED}.24.249:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (primary)
- {BLOCKED}.{BLOCKED}.2.37:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (secondary)
- {BLOCKED}.{BLOCKED}.3.37:443 (Tenorshare CDN, Cloudflare) → second-stage installer download (secondary)
- a23-11-39-161.deploy.static.{BLOCKED}technologies.com:80 → Authenticode CRL/OCSP for signature validation
SOLUTION
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.
Step 3
Remove PUA.Win32.PDNob.A by using its own Uninstall option
Step 4
Delete this registry key
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\
- Downloader2.5.0
- Downloader2.5.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\
- GuidGuidold
- GuidGuidold
- In HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\
- {Tenorshare PDNob}_is1
- {Tenorshare PDNob}_is1
- In HKEY_CLASSES_ROOT\
- PDNob PDF Editor.Menu.EXE
- PDNob PDF Editor.Menu.EXE
- In HKEY_CLASSES_ROOT\SystemFileAssociations\.pdf\shell\
- PDNob PDF Editor.Menu.EXE
- PDNob PDF Editor.Menu.EXE
- In HKEY_CURRENT_USER\Software\Classes\.pdf\OpenWithProgids\
- PDNob PDF Editor.Menu.EXE
- PDNob PDF Editor.Menu.EXE
Step 5
Search and delete this file
- %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe
- %User Temp%\pdfeditor_ts\pdfeditor_ts_1.0.0.0.exe.xml
- %User Temp%\pdfeditor_ts\galog.json
- %User Temp%\pdfeditor_ts\pdfeditor_ts_.log
- %User Temp%\Tenorshare PDNob_Setup_.log
- %User Temp%\Ext.dll
- %User Temp%\findSoftRes.txt
- %Public%\Desktop\Tenorshare PDNob.lnk
- %Common Programs%\Microsoft\Windows\Start Menu\Programs\Tenorshare PDNob.lnk
- %Common Programs%\Microsoft\Windows\Start Menu\Programs\(Default)\Uninstall Tenorshare PDNob.lnk
Step 6
Search and delete these folders
- %User Temp%\pdfeditor_ts\
- %User Temp%\is-.tmp\
- %Program Files% (x86)\Tenorshare\Tenorshare PDNob\
- %AppDataLocal%\PDNob PDF Editor\
Step 7
Scan your computer with your Trend Micro product to delete files detected as PUA.Win32.PDNob.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.
