Home Malware Programs Adware Riversoft

Riversoft

Posted: March 28, 2006

Riversoft is an adware application that shows commercial pop-up advertisements while you surf the Internet. The spyware doesn't spread and must be manually installed. It may arrive with some ad-supported software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 csa.dll
    2 x0ff.cab
    3 x0ff.dll
    4 x0ff0n.exe
    5 x2ff.dll
    6 x2ff.inf

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTAppIDcsa.DLLHKEY_CLASSES_ROOTAppIDx0ff.DLLHKEY_CLASSES_ROOTAppIDx2ff.DLLHKEY_CLASSES_ROOTcsa.accelHKEY_CLASSES_ROOTcsa.accel.1HKEY_CLASSES_ROOTx0ff.XbrowseHKEY_CLASSES_ROOTx0ff.Xbrowse.1HKEY_CLASSES_ROOTx2ff.XbrowseHKEY_CLASSES_ROOTx2ff.Xbrowse.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}FEC81DDE-1320-4027-8D1D-72753D27B4F3F81F7F91-8BA8-47DD-80FE-A262A4C8A9851D1A0231-322A-4024-A282-697bF547970EF1EA6966-79FB-47FA-AB97-8ED1A8D89DE4B0C5E55E-53DF-4966-90A0-912D34CB64A7248D0792-644C-403B-8525-AA2877603204D319662B-D5BF-4538-ADF3-8D3E36362608AC109D01-32D6-4EB5-8300-D3C5EBAC7C83ABD45F35-2E4C-44C0-A075-6EF1DE75398ED1BB73A7-5D35-48C9-94C0-D0BD624B0F5DD137514C-FFFA-492A-933B-D29145B7A468CCB76C32-C755-4859-B195-73DB23D55AC4
Loading...