84,488,480 programs installed

Should I remove PC Data App?

What percent of users and experts removed it?
79% remove it21% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Global Rank #4,544
United States Rank #23,241
Reach 0.1160%
Lifespan of installation (until removal)
< 144.94 days
818.20 days >
Average installed length: 429.90 days

PC Data App

What is PC Data App?

The software is a Trojan Bitcoin miner that utilizes the open source CGMiner utility. The Trojan Bitcoin miner is an invasive multiple component malware infection. This is a potentially unwanted program that installs malware on the user's PC using the file start.vbs to launch PCDApp\cgminer.exe. Once running it utilizes the computer's GPU resources in order to mine for Bitcoins without the user's knowledge. This will seriously impact the performance of the user's PC.

Overview

Upon being installed, the software adds a Windows Service which is designed to run continuously in the background. Manually stopping the service has been seen to cause the program to stop functing properly. It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. The software is designed to connect to the Internet and adds a Windows Firewall exception in order to do so without being interfered with. The primary executable is named StartHelp.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 33 files and is usually about 1.72 MB (1,800,285 bytes).
  • Malware detected in the program
  • Connects to the Internet
  • Adds a background Windows Service
  • Most users and experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in PC Data App.
StartHelp.exe (b3cf0d13d2542db5f0af63b7940f8177) has been flagged by the following 2 scanners:
Anti-Virus softwareVersionDetection
SUPERAntiSpyware 10532 Trojan.Agent/Gen-VBInject
VIPRE Antivirus 27622 Trojan.Win32.Generic!BT
dgen.exe (6c703d7d0f984a5253a494ae3e1594be) has been flagged by the following 33 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Trojan.Generic.11326041
Agnitum Outpost 5.5.1.3 Riskware.Agent!
AhnLab-V3 2014.06.21.00 Unwanted/Win32.BitCoinMiner
Avira AntiVir 7.11.155.214 TR/Rogue.11326041
Antiy-AVL 1.0.0.1 Trojan/Win32.TSGeneric
avast! 8.0.1489.320 Win32:Malware-gen
Baidu-International 3.5.1.41473 Hacktool.Win32.BitCoinMiner.45
Bitdefender 7.2 Trojan.Generic.11326041
ByteHero BDV 1.0.0.1 Trojan.Malware.KillAV.Gen.001
CAT-QuickHeal 14.00 RiskTool.BitCoinMiner.r8 (Not a Virus)
Comodo Security 18606 UnclassifiedMalware
Dr.Web 7.0.7.12100 Tool.BtcMine.306
Emsisoft Anti-Malware 3.0.0.600 Trojan.Generic.11326041 (B)
ESET-NOD32 9973 a variant of Win32/BitCoinMiner.BS
Fortinet FortiGate 5.1.152.0 W32/BitCoinMiner.BS
F-Secure 11.0.19100.45 Trojan.Generic.11326041
G Data 24 Trojan.Generic.11326041
IKARUS anti.virus T3.1.6.1.0 not-a-virus:RiskTool.Win32.BitCoinMiner
K7 AntiVirus 9.180.12463 Trojan ( 0049990a1 )
K7GW 9.180.12463 Trojan ( 0049990a1 )
McAfee 6.0.4.564 W32/CoinMiner!6C703D7D0F98
McAfee-GW-Edition 2013 Heuristic.LooksLike.Win32.Suspicious.J!89
MicroWorld-eScan 12.0.250.0 Trojan.Generic.11326041
NANO AntiVirus 0.28.0.60253 Riskware.Win32.BtcMine.cwbwaz
nProtect 2014-06-20.01 Trojan.Generic.11326041
Panda Antivirus 10.0.3.5 Trj/Dtcontx.M
Qihoo-360 1.0.0.1015 Win32/Trojan.721
Sophos 4.98.0 Mal/Generic-S
Symantec 20131.1.5.61 Trojan.ADH
Trend Micro 9.740.0.1012 HKTL_COINMINE
TrendMicro-HouseCall 9.700.0.1001 HKTL_COINMINE
VIPRE Antivirus 30478 Trojan.Win32.Generic!BT
ViRobot 2011.4.7.4223 Trojan.Win32.S.Agent.173070
       View all 35 all detections
Bundled relationships

Program detailsProgram details

Installation folder: C:\Program Files\pcdapp
Uninstaller: "C:\Program Files\PCDApp\uninstaller.exe"
Estimated size: 1.72 MB

Program filesFiles installed by PC Data App

Program executable:StartHelp.exe (Malware detected)
Path:C:\Program Files\pcdata\StartHelp.exe
MD5:b3cf0d13d2542db5f0af63b7940f8177
Additional files:
  • (Malware detected) dgen.exe
  • (Malware detected) StartHelp.exe
  • uninstaller.exe
  • wget.exe

Program behaviorsBehaviors exhibited

Service
  • StartHelp.exe runs as a service named 'Protect Monitor' (ProtectMonitor).
3 Windows Firewall Allowed Programs
  • StartHelp.exe is added as a firewall exception for 'C:\Program Files\PCDApp\StartHelp.exe'.
  • wget.exe is added as a firewall exception for 'C:\Program Files\PCDApp\wget.exe'.
  • dgen.exe is added as a firewall exception for 'C:\Program Files\PCDApp\dgen.exe'.
Network connections
  • dgen.exe connects to 128.199.210.17 (port 8003).

Program resource utilizationResource utilization averages

dgen.exe
Memory:27.98 MB
21.09 MB average
Total CPU:0.0000936320%
0.031193% average
Kernel CPU:0.00006247%
0.016088% average
User CPU:0.00003117%
0.015104% average

How do I remove PC Data App?

You can uninstall PC Data App from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program PC Data App, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove PC Data App.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

HOW IT RUNS
Windows Service? Yes
(Installs a service)
 
USER ACTIONS
Uninstall it 79%
Keep it 21%
 
GLOBAL RANK
#4,544

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 67.42%
Windows 10 23.57%
Windows XP 7.26%
Windows Vista 1.71%
Windows Server 2003 0.04%
Which OS releases does it run on?
Windows 7 Ultimate 30.83%
Windows 7 Professional 14.62%
Windows 7 Home Premium 14.49%
Microsoft Windows XP 7.16%
Windows 8.1 Pro 4.48%
Windows 8.1 4.08%

Distribution by countryGeography

8.00% of installs come from Brazil
Which countries install it?
  Brazil 8.00%
  India 6.49%
  MA 5.51%
  Turkey 4.53%
  Saudi Arabia 4.40%
  Indonesia 4.18%
  United States 3.38%
  Romania 3.02%
  DZ 2.75%
  Malaysia 2.71%
  Philippines 2.35%
  Iran 2.31%
  Thailand 1.87%
  Czech Republic 1.78%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 24.44%
Acer 20.25%
Dell 18.59%
ASUS 8.83%
Lenovo 6.84%
GIGABYTE 6.24%
Samsung 6.18%
Toshiba 5.18%
Intel 1.59%
Sahara 1.06%
American Megatrends 0.80%
Common models
HP Pavilion dv6 Notebook ... 4.95%
HP Pavilion g6 Notebook P... 3.80%
Dell Inspiron 3521 3.47%
Dell Inspiron N5010 3.14%
Dell Inspiron N5110 2.97%
Samsung 300E4C/300E5C/300... 2.64%

comments1 comment

user comment
expert comment
SteveG (Expert)over a year ago
There are trojans with the purpose of sneaking mining software into systems.