Análisis realizado por : Pearl Charlaine Espejo   

 Alias

PUA.PCPowerSpeed (Symantec)

 Plataforma:

Windows

 Riesgo general:
 Potencial de destrucción:
 Potencial de distribución:
 Infección divulgada:
 Revelación de la información:
Bajo
Medio
High
Crítico

  • Tipo de malware
    Potentially Unwanted Application

  • Destructivo?
    No

  • Cifrado
     

  • In the Wild:

  Resumen y descripción

Puede haberlo instalado manualmente un usuario.

  Detalles técnicos

Tamaño del archivo 4,041,400 bytes
Tipo de archivo EXE
Residente en memoria No
Fecha de recepción de las muestras iniciales 24 Oct 2015

Detalles de entrada

Puede haberlo instalado manualmente un usuario.

Instalación

Agrega las carpetas siguientes:

  • %User Temp%\is-{random characters}.tmp\{malware filename}.tmp
  • %User Temp%\is-{random characters}.tmp\_isetup
  • %Program Files%\PCPowerSpeed
  • %Application Data%\PCPowerSpeed
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\PC Power Speed

(Nota: %User Temp% es la carpeta Temp del usuario activo, que en el caso de Windows 2000, XP y Server 2003 suele estar en C:\Documents and Settings\{nombre de usuario}\Local Settings\Temp).

. %Program Files% es la carpeta Archivos de programa predeterminada, que suele estar en C:\Archivos de programa).

. %Application Data% es la carpeta Application Data del usuario activo, que en el caso de Windows 98 y ME suele estar ubicada en C:\Windows\Profiles\{nombre de usuario}\Application Data, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario}\Application Data y en el caso de Windows 2000, XP y Server 2003 en C:\Documents and Settings\{nombre de usuario}\Local Settings\Application Data).

)

Infiltra los archivos siguientes:

  • %User Temp%\is-{random characters}.tmp\_isetup\_RegDLL.tmp
  • %User Temp%\is-{random characters}.tmp\_isetup\_shfoldr.dll
  • %Program Files%\PCPowerSpeed\unins000.dat
  • %Program Files%\PCPowerSpeed\unins000.exe
  • %Program Files%\PCPowerSpeed\unins000.msg
  • %Program Files%\PCPowerSpeed\PCPowerSpeed.exe
  • %Program Files%\PCPowerSpeed\PCPowerTray.exe
  • %Application Data%\PCPowerSpeed\faq.tmp
  • %Desktop%\PC Power Speed - Optimize Your PC.lnk
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\PC Power Speed\PC Power Speed.lnk
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\PC Power Speed\PCPowerSpeed.com.url
  • %ProgramData%\Microsoft\Windows\Start Menu\Programs\PC Power Speed\Uninstall PC Power Speed.lnk

Técnica de inicio automático

Agrega las siguientes entradas de registro para permitir su ejecución automática cada vez que se inicia el sistema:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
PCPowerSpeed = ""%Program Files%\PCPowerSpeed\PCPowerTray.exe" /startup"

Otras modificaciones del sistema

Agrega las siguientes entradas de registro como parte de la rutina de instalación:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1

HKEY_CURRENT_USER\Software\Microsoft\
Direct3D

HKEY_CURRENT_USER\Software\Microsoft\
Direct3D\MostRecentApplication

HKEY_CURRENT_USER\Software\PCPowerSpeed

HKEY_CURRENT_USER\Software\PCPowerSpeed\
AppMessages

Agrega las siguientes entradas de registro:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Inno Setup: Setup Version = "5.3.8 (a)"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Inno Setup: App Path = "%Program Files%\PCPowerSpeed"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
InstallLocation = "%Program Files%\PCPowerSpeed\"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Inno Setup: Icon Group = "PC Power Speed"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Inno Setup: User = "{username}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Inno Setup: Language = "en"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
DisplayName = "PC Power Speed 2.1.0.108"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
DisplayIcon = "%Program Files%\PCPowerSpeed\PCPowerSpeed.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
UninstallString = "%Program Files%\PCPowerSpeed\unins000.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
QuietUninstallString = ""%Program Files%\PCPowerSpeed\unins000.exe" /SILENT"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
DisplayVersion = "2.1.0.108"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
Publisher = "Crawler Group, LLC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
URLInfoAbout = "http://www.PCPowerSpeed.com/"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
HelpLink = "http://www.PCPowerSpeed.com/"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
URLUpdateInfo = "http://www.PCPowerSpeed.com/"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
NoModify = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
NoRepair = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
InstallDate = "{Installation date}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
MajorVersion = "2"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
MinorVersion = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1
EstimatedSize = "14006"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
StartPage\NewShortcuts
%Application Data%\Microsoft\Windows\Start Menu\Programs\PC Power Speed\PC Power Speed.lnk = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
StartPage\NewShortcuts
%ProgramData%\Microsoft\Windows\Start Menu\Programs\PC Power Speed\PC Power Speed.lnk = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Direct3D\MostRecentApplication
Name = "PCPowerSpeed.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
INSTALL = "{hex value}"

HKEY_CURRENT_USER\Software\PCPowerSpeed
SCHEDULE_SCAN = "7"

HKEY_CURRENT_USER\Software\PCPowerSpeed
STARTUP_SCAN = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
SHOW_RESULTS = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
SHOW_TRAY = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
DELAY_STARTUP = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
CREATE_SYSTEMRP = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
CHECK_FOR_UPDATES = "1"

HKEY_CURRENT_USER\Software\PCPowerSpeed
LAST_UPDATE = "{hex value}"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
LANGUAGE = "en"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
INSTCFG = "29"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
UID = "{UID}"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
PARAM{number} = "{hex value}"

HKEY_CURRENT_USER\Software\PCPowerSpeed
OTF = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\PCPowerSpeed
SERVER_STATUS_TYPE = ""