Analysé par: Michael Jay Villanueva   

 

PUP.Optional.RegistryReviver (Malwarebytes); Win64/RegistryReviver.A (ESET-NOD32)

 Plate-forme:

Windows

 Overall Risk:
 Dommages potentiels: :
 Distribution potentielle: :
 reportedInfection:
 Information Exposure Rating::
Faible
Medium
Élevé
Critique

  • Type de grayware:
    Potentially Unwanted Application

  • Destructif:
    Non

  • Chiffrement:
     

  • In the wild::
    Oui

  Overview

Wird möglicherweise manuell von einem Benutzer installiert.

Ändert Zoneneinstellungen von Internet Explorer.

  Détails techniques

File size: 10,714,056 bytes
File type: EXE
Date de réception des premiers échantillons: 23 février 2017

Übertragungsdetails

Wird möglicherweise manuell von einem Benutzer installiert.

Installation

Schleust die folgenden Dateien ein:

  • %System Root%\257e493e-fb12-4d60-a596-554667391420.exe
  • %Program Files%\ReviverSoft\Smart Monitor\msvcp100.dll
  • %Program Files%\ReviverSoft\Smart Monitor\msvcr100.dll
  • %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitor.exe
  • %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitor.mab
  • %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitorService.exe
  • %Program Files%\ReviverSoft\Smart Monitor\ReviverSoftSmartMonitorService.mab
  • %Program Files%\ReviverSoft\Smart Monitor\apps.json
  • %Program Files%\ReviverSoft\Smart Monitor\SystemInfo-vc100-mt.dll
  • %Program Files%\ReviverSoft\Smart Monitor\SystemInfo-vc100-mt.mab
  • %Program Files%\ReviverSoft\Smart Monitor\Plugins\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4.dll
  • %Program Files%\ReviverSoft\Smart Monitor\Plugins\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4.dll
  • %Program Files%\ReviverSoft\Smart Monitor\Plugins\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4\5ae6acfc-937d-43b9-b91e-954fa7ad3f06.1.0.0.4.mab
  • %Program Files%\ReviverSoft\Smart Monitor\Plugins\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4\78EB6AEF-BCAB-4E11-9315-3B06CCAA1BDD.1.0.0.4.mab
  • %Program Files%\ReviverSoft\Smart Monitor\Uninstall.exe
  • %Program Files%\ReviverSoft\Registry Reviver\nfo
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Bulgarian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Croatian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Czech2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Danish2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Dutch2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\English.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\English1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\English2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Finnish2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\French.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\French1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\French2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\German.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\German1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\German2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Greek2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Hungarian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Indonesian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Italian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Japanese2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Norwegian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Polish2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Portuguese2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Romanian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Russian2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\SimpChinese2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Spanish2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Swedish2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Thai2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\TradChinese2
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish.xml
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish1
  • %Program Files%\ReviverSoft\Registry Reviver\defaults\Turkish2
  • %Program Files%\ReviverSoft\Registry Reviver\binary_archive_converter.exe
  • %Program Files%\ReviverSoft\Registry Reviver\msvcp100.dll
  • %Program Files%\ReviverSoft\Registry Reviver\msvcr100.dll
  • %Program Files%\ReviverSoft\Registry Reviver\FileExtensionManager-vc100-mt.dll
  • %Program Files%\ReviverSoft\Registry Reviver\RegistryReviver.exe
  • %Program Files%\ReviverSoft\Registry Reviver\RegistryReviverUpdater.exe
  • %Program Files%\ReviverSoft\Registry Reviver\Uninstall.exe
  • %Program Files%\ReviverSoft\Registry Reviver\tray.exe
  • %Program Files%\ReviverSoft\Registry Reviver\ReviverSoftSmartMonitorSetup.exe
  • %ProgramData%\ReviverSoft\Registry Reviver\{SID}\Settings.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\CommonSettings.xml
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver\Uninstall.lnk
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver\Registry Reviver.lnk
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Bulgarian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Croatian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Czech.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Danish.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Dutch.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\English.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Finnish.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\French.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\German.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Greek.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Hungarian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Indonesian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Italian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Japanese.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Korean.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Norwegian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Polish.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Portuguese.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Romanian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Russian.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\SimpChinese.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Spanish.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Swedish.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Thai.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\TradChinese.xml
  • %ProgramData%\ReviverSoft\Registry Reviver\Language\Turkish.xml
  • %Windows%\Tasks\Start Registry Reviver for {Computer Name}@{Username}(logon).job
  • %Desktop%\Registry Reviver.lnk
  • %User Temp%\ns{random 1}.tmp
  • %User Temp%\ns{random 2}.tmp\System.dll
  • %User Temp%\ns{random 2}.tmp\ga_utility.exe
  • %User Temp%\ns{random 2}.tmp\nsExec.dll
  • %User Temp%\ns{random 2}.tmp\ns18A1.tmp
  • %User Temp%\ns{random 2}.tmp\ioSpecial.ini
  • %User Temp%\ns{random 2}.tmp\modern-wizard.bmp
  • %User Temp%\ns{random 2}.tmp\nsEnvVariables.dll
  • %User Temp%\ns{random 2}.tmp\InstallOptions.dll
  • %User Temp%\ns{random 2}.tmp\linker.dll
  • %User Temp%\ns{random 2}.tmp\nsProcess.dll
  • %User Temp%\ns{random 2}.tmp\nsSessionSIDW.dll
  • %User Temp%\ns{random 3}.tmp\execDos.dll
  • %User Temp%\ns{random 3}.tmp\System.dll
  • %User Temp%\ns{random 3}.tmp\nsProcess.dll

(Hinweis: %System Root% ist der Stammordner, normalerweise C:\. Dort befindet sich auch das Betriebssystem.. %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %Windows% ist der Windows Ordner, normalerweise C:\Windows oder C:\WINNT.. %Desktop% ist der Ordner 'Desktop' für den aktuellen Benutzer, normalerweise C:\Windows\Profile\{Benutzername}\Desktop unter Windows 98 und ME, C:\WINNT\Profile\{Benutzername}\Desktop unter Windows NT und C:\Dokumente und Einstellungen\{Benutzername}\Desktop unter Windows 2000, XP und Server 2003.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.)

Erstellt die folgenden Ordner:

  • %Program Files%\ReviverSoft
  • %Program Files%\ReviverSoft\Smart Monitor
  • %Program Files%\ReviverSoft\Smart Monitor\Plugins
  • %Program Files%\ReviverSoft\Registry Reviver
  • %ProgramData%\ReviverSoft
  • %ProgramData%\ReviverSoft\Registry Reviver
  • %ProgramData%\ReviverSoft\Registry Reviver\{SID}
  • %ProgramData%\ReviverSoft\Registry Reviver\Language
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\ReviverSoft\Registry Reviver
  • %User Temp%\ns{random 2}.tmp
  • %User Temp%\ns{random 3}.tmp

(Hinweis: %Program Files%ist der Standardordner 'Programme', normalerweise C:\Programme.. %User Temp% ist der Ordner 'Temp' des aktuellen Benutzers, normalerweise C:\Dokumente und Einstellungen\{Benutzername}\Lokale Einstellungen\Temp unter Windows 2000, XP und Server 2003.)

Andere Systemänderungen

Fügt die folgenden Registrierungseinträge hinzu:

HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
AppDir = "%Program Files%\ReviverSoft\Registry Reviver"

HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
Language = "English.xml"

HKEY_LOCAL_MACHINE\SOFTWARE\Registry Reviver
OriginalLang = "English.xml"

Änderung der Startseite von Webbrowser und Suchseite

Ändert Zoneneinstellungen von Internet Explorer.

  Solutions

Moteur de scan minimum: 9.850
SSAPI Pattern File: 1.865.00
SSAPI Pattern Release Date: 17 août 2017
Participez à notre enquête!