Home Malware Programs Potentially Unwanted Programs (PUPs) Lite PDF Reader

Lite PDF Reader

Posted: October 12, 2017

Threat Metric

Ranking: 13,558
Threat Level: 1/10
Infected PCs: 1,691
First Seen: October 12, 2017
Last Seen: September 13, 2023
OS(es) Affected: Windows

PDF readers are a utility that every user needs to be able to view one of the most widely spread file formats used for documents. However, you should always stick to using reputable software that has proven its worth through the years, because trusting newly released tools like the Lite PDF Reader may end up causing you a mild headache. This software is advertised as a lightweight and free PDF viewing software suite that users are guaranteed to enjoy. While their website seems well-crafted and legitimate, the installer of the Lite PDF Reader reveals some worrisome facts.

First of all, the software comes with a trial period of 30 days after which the application will deactivate itself. The only way to avoid this is to authorize the installer to modify your default browser's homepage to Fidonav.com, a search engine that has been linked to browser hijacking software in the past. Regardless if users authorize or decline this change, the Lite PDF Reader will continue to carry out other suspicious operations. The program creates a service to launch itself when Windows starts automatically, and it may connect to remote servers based in Russia and the US - Reliablesever.online, Rtp.tools1000.com, Report.litepdfreader.net, Download.reliablesever.online silently. While these hosts are not linked to a threat distribution campaign, they might be used to serve ads, therefore reducing the quality of your Web browsing experience and exposing you to dubious digital content.

The Lite PDF Reader appears to be listed as a Potentially Unwanted Program (PUP), but it also seems to poses the ability to inject unwelcomed ads in the user's Web browser. Furthermore, online threat analysis services show that the Lite PDF Reader requires permissions and executes actions that are not typical for legitimate software, which might mean that it possesses the ability to be even more threatening. It is recommended to stay away from this software or, if you've already installed it, to use a credible anti-virus software suite to get rid of all its components.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 6.59 MB (6596128 bytes)
MD5: e2b3a73570c40537c5ff441658592410
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 16, 2017

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PUBLIC%\Documents\LitePDF\userconf.dbHKEY..\..\..\..{RegistryKeys}SOFTWARE\LitePDFReaderSYSTEM\ControlSet001\services\LitePDFReaderServiceSYSTEM\ControlSet002\services\LitePDFReaderServiceSYSTEM\CurrentControlSet\services\LitePDFReaderServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{1C5BCD06-8E5D-445e-9C18-E74748BA0F8B}

Additional Information

The following directories were created:
%APPDATA%\LitePDFReader%PROGRAMFILES%\LitePDFReader%PROGRAMFILES(x86)%\LitePDFReader
Loading...