PUA_REVIVER.GA
PUP.Optional.RegistryReviver (Malwarebytes); Win64/RegistryReviver.A (ESET-NOD32)
Windows
Malware-Typ:
Potentially Unwanted Application
Zerstrerisch?:
Nein
Verschlsselt?:
In the wild::
Ja
Überblick
Wird möglicherweise manuell von einem Benutzer installiert.
Ändert Zoneneinstellungen von Internet Explorer.
Technische Details
Übertragungsdetails
Wird möglicherweise manuell von einem Benutzer installiert.
Installation
Schleust die folgenden Dateien ein:
- %System Root%\257e493e-fb12-4d60-a596-554667391420.exe
- %Program Files%\ReviverSoft\Smart Monitor\msvcp100.dll
- %Program Files%\ReviverSoft\Smart Monitor\msvcr100.dll
- %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitor.exe
- %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitor.mab
- %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitorService.exe
- %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitorService.mab
- %Program Files%\ReviverSoft\Smart Monitor\apps.json
- %Program Files%\ReviverSoft\Smart Monitor\SystemInfo-vc100-mt.dll
- %Program Files%\ReviverSoft\Smart Monitor\SystemInfo-vc100-mt.mab
- %Program Files%\ReviverSoft\Smart Monitor\Plugins\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4.dll
- %Program Files%\ReviverSoft\Smart Monitor\Plugins\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4.dll
- %Program Files%\ReviverSoft\Smart Monitor\Plugins\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4.mab
- %Program Files%\ReviverSoft\Smart Monitor\Plugins\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4.mab
- %Program Files%\ReviverSoft\Smart Monitor\Uninstall.exe
- %Program Files%\ReviverSoft\Registry Reviver\nfo
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\English.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\English1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\English2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\French.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\French1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\French2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\German.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\German1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\German2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese2
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish.xml
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish1
- %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish2
- %Program Files%\ReviverSoft\Registry Reviver\binary_archive_converter.exe
- %Program Files%\ReviverSoft\Registry Reviver\msvcp100.dll
- %Program Files%\ReviverSoft\Registry Reviver\msvcr100.dll
- %Program Files%\ReviverSoft\Registry Reviver\FileExtensionManager-vc100-mt.dll
- %Program Files%\ReviverSoft\Registry Reviver\RegistryReviver.exe
- %Program Files%\ReviverSoft\Registry Reviver\RegistryReviverUpdater.exe
- %Program Files%\ReviverSoft\Registry Reviver\Uninstall.exe
- %Program Files%\ReviverSoft\Registry Reviver\tray.exe
- %Program Files%\ReviverSoft\Registry Reviver\ReviverSoftSmartMonitorSetup.exe
- %ProgramData%\ReviverSoft\Registry Reviver\{SID}\Settings.xml
- %ProgramData%\ReviverSoft\Registry Reviver\CommonSettings.xml
- %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver\Uninstall.lnk
- %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver\Registry Reviver.lnk
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Bulgarian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Croatian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Czech.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Danish.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Dutch.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\English.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Finnish.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\French.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\German.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Greek.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Hungarian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Indonesian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Italian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Japanese.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Korean.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Norwegian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Polish.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Portuguese.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Romanian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Russian.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\SimpChinese.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Spanish.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Swedish.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Thai.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\TradChinese.xml
- %ProgramData%\ReviverSoft\Registry Reviver\Language\Turkish.xml
- %Windows%\Tasks\Start Registry Reviver for {Computer Name}@{Username}(logon).job
- %Desktop%\Registry Reviver.lnk
- %User Temp%\ns{random 1}.tmp
- %User Temp%\ns{random 2}.tmp\System.dll
- %User Temp%\ns{random 2}.tmp\ga_utility.exe
- %User Temp%\ns{random 2}.tmp\nsExec.dll
- %User Temp%\ns{random 2}.tmp\ns18A1.tmp
- %User Temp%\ns{random 2}.tmp\ioSpecial.ini
- %User Temp%\ns{random 2}.tmp\modern-wizard.bmp
- %User Temp%\ns{random 2}.tmp\nsEnvVariables.dll
- %User Temp%\ns{random 2}.tmp\InstallOptions.dll
- %User Temp%\ns{random 2}.tmp\linker.dll
- %User Temp%\ns{random 2}.tmp\nsProcess.dll
- %User Temp%\ns{random 2}.tmp\nsSessionSIDW.dll
- %User Temp%\ns{random 3}.tmp\execDos.dll
- %User Temp%\ns{random 3}.tmp\System.dll
- %User Temp%\ns{random 3}.tmp\nsProcess.dll
(Hinweis: %System Root% ist der Stammordner, normalerweise C:\. Dort befindet sich auch das Betriebssystem.. %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %Windows% ist der Windows Ordner, normalerweise C:\Windows oder C:\WINNT.. %Desktop% ist der Ordner 'Desktop' für den aktuellen Benutzer, normalerweise C:\Windows\Profile\{Benutzername}\Desktop unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Desktop unter Windows NT und C:\Dokumente und Einstellungen\{Benutzername}\Desktop unter Windows 2000, XP und Server 2003.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.)
Erstellt die folgenden Ordner:
- %Program Files%\ReviverSoft
- %Program Files%\ReviverSoft\Smart Monitor
- %Program Files%\ReviverSoft\Smart Monitor\Plugins
- %Program Files%\ReviverSoft\Registry Reviver
- %ProgramData%\ReviverSoft
- %ProgramData%\ReviverSoft\Registry Reviver
- %ProgramData%\ReviverSoft\Registry Reviver\{SID}
- %ProgramData%\ReviverSoft\Registry Reviver\Language
- %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft
- %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver
- %User Temp%\ns{random 2}.tmp
- %User Temp%\ns{random 3}.tmp
(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.)
Andere Systemänderungen
Fügt die folgenden Registrierungseinträge hinzu:
HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
AppDir = "%Program Files%\ReviverSoft\Registry Reviver"
HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
Language = "English.xml"
HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
OriginalLang = "English.xml"
Änderung der Startseite von Webbrowser und Suchseite
Ändert Zoneneinstellungen von Internet Explorer.