registryreviversetup.exe

Registry Reviver

ReviverSoft

The application registryreviversetup.exe, “Registry Reviver installer” by ReviverSoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Registry Reviver by ReviverSoft LLC. The file has been seen being downloaded from www.reviversoft.com and multiple other hosts.
Publisher:
ReviverSoft LLC  (signed by ReviverSoft)

Product:
Registry Reviver

Description:
Registry Reviver installer

Version:
3.0.1.142

MD5:
517b8f91fd16035053df38a5f33efb51

SHA-1:
c632256e9f49954fb3e9efeb61c841ba3026dbc3

SHA-256:
47e53fcb9924caf90585dec56ab13a0310053e7d881976cfeef063fbe5737859

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 7:49:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.ReviverSoft.U
14.1.24.19

File size:
5.1 MB (5,329,336 bytes)

Product version:
3.0.1.142

Copyright:
ReviverSoft LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\reviversoft\registry reviver\registryreviversetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/12/2011 3:00:00 AM

Valid to:
7/2/2014 2:59:59 AM

Subject:
CN=ReviverSoft, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ReviverSoft, L=Walnut Creek, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67CBBBC287729969E701CBDA1DED7CA8

File PE Metadata
Compilation timestamp:
4/10/2010 3:19:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:7AAhTG5FRBraLbUVQE9dU+eUGFd020UhAXmFqw9c5BUrTz5N+aB4uvh:7ACTuFa/UCEw02Nl9RN+0vh

Entry address:
0x33E9

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 78, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, 90, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, 80, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9650

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file registryreviversetup.exe has been discovered within the following programs.

Registry Reviver  by ReviverSoft LLC
Registry Reviver is registry utility whose purported purpose is to remove redundant items from the Windows registry.
www.reviversoft.com/registry-reviver
48% remove it
 
Powered by Should I Remove It?

The file registryreviversetup.exe has been seen being distributed by the following 6 URLs.

http://www.reviversoft.com/downloads/CID/PPC-YAHJP/PAR/.../RegistryReviverSetup.exe

Remove registryreviversetup.exe - Powered by Reason Core Security