registryreviversetup_3.0.1.144_co2.exe

Registry Reviver

ReviverSoft

The executable registryreviversetup_3.0.1.144_co2.exe, “Registry Reviver installer” has been detected as malware by 3 anti-virus scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
ReviverSoft LLC  (signed by ReviverSoft)

Product:
Registry Reviver

Description:
Registry Reviver installer

Version:
3.0.1.144

MD5:
4d90d8d4bc041dc44b308c828905e8a4

SHA-1:
24b72892e4780bfa01eb915df278750a267dd5e0

SHA-256:
71e272ce25c5d2ee5f93ca00208671a5416926d3a878328215876d78a6d2fc61

Scanner detections:
3 / 68

Status:
Malware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/27/2024 1:13:44 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

Dr.Web
riskware program Program.Unwanted.705
9.0.1.05190

Reason Heuristics
PUP.OpenCandy.Bundler (L)
16.12.9.10

File size:
5.1 MB (5,330,760 bytes)

Product version:
3.0.1.144

Copyright:
ReviverSoft LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\opencandy\920041dae50a493cb0e2444536538cfe\registryreviversetup_3.0.1.144_co2.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/12/2011 8:00:00 AM

Valid to:
7/2/2014 7:59:59 AM

Subject:
CN=ReviverSoft, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ReviverSoft, L=Walnut Creek, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67CBBBC287729969E701CBDA1DED7CA8

File PE Metadata
Compilation timestamp:
4/10/2010 8:19:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:TAAhUnG5SunsY7dLMRvmXsrxhmjS4vx1auirUMQMNTuV733vP8FJ22FBX0WlQfDP:TACUnuSunNrXsYZnauQ5lNTuRMzBXbyr

Entry address:
0x33E9

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 78, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, 90, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, 80, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9652

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

Remove registryreviversetup_3.0.1.144_co2.exe - Powered by Reason Core Security