Avira 病毒搜索

PUA/Iolo.EL.3

  • 名称
    PUA/Iolo.EL.3
  • 发现日期
    2017年12月13日
  • 类型
    Potential Unwanted Application
  • 影响
     
  • 报告的感染
     
  • 操作系统
    Windows
  • VDF 版本
    7.14.37.244 (2017-12-13 11:16)

此类检测标志表示可能有害的应用程序 (PUA),它们可能会危及用户的隐私和本地系统的安全性。它们都是合法的应用程序,通常会在用户安装其最初想要安装的软件时,试图利用社交工程来使用户安装额外的产品和服务。PUA 类的应用程序是软件、广告或涉及一个或多个违规行为和/或属性的网站的结果。可在 http://www.avira.com/en/potentially-unwanted-applications 上获取完整的 PUA 列表。此类检测结果不一定意味着文件就是恶意软件。但是,如果该文件在用户不知情的情况下安装到用户的系统中,则用户的隐私或系统的安全性可能会遭到泄露或破坏。仅建议了解存在的风险和如何使用这些应用程序的高级用户禁用此检测。

  • VDF
    7.14.37.244 (2017-12-13 11:16)
  • 文件
    创建以下文件:
    • %SYSDIR%\mfc45.dat
    • %WINDIR%\SysWOW64\mfc45.dat
    更改以下文件:
    • %WINDIR%\SysWOW64\mfc45.dat
    删除以下文件:
    • %TEMPDIR%\%executed_sample_name%.madExcept
    • %TEMPDIR%
    加载以下驱动程序:
    • %WINDIR%\Globalization\Sorting\sortdefault.nls
    • %WINDIR%\SysWOW64\mfc45.dat
    • %TEMPDIR%\%executed_sample%
    • %WINDIR%\SysWOW64\en-US\KERNELBASE.dll.mui
    执行以下文件:
    • %WINDIR%\Globalization\Sorting\sortdefault.nls
    • %WINDIR%\SysWOW64\mfc45.dat
    • %TEMPDIR%\%executed_sample%
    • %WINDIR%\SysWOW64\en-US\KERNELBASE.dll.mui
  • 注册表
    会添加以下注册表项目:
    • HKEY_CURRENT_USER\Software\Embarcadero\Locales (""%executed_sample%"": ""en"")
    • HKEY_CURRENT_USER\Software\Embarca
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications (""MaxSize"": "dword:00100000") (""Retention"": "dword:00000000")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\System Mechanic (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Service Manager (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\System Shield (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\ActiveCare (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Search and Recover (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\DriveScrubber (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Installer (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\System Guard (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Launch Manager (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Tune-Up Definitions (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Governor (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\iolo Applications\Memory Mechanic (""EventMessageFile"": ""%APPDATA%\\Roaming\\iolo\\EventMsg.dll"") (""TypesSupported"": "dword:00000007")
    • HKEY_CURRENT_USER\Software\Embarcadero\Locales ("%TEMPDIR%\%executed_sample%": "en")
    • HKEY_CURRENT_USER\Software\Embarcadero\Locales
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications ("MaxSize": "1048576")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications ("Retention": "0")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic ("TypesSupported": "7")
    会更改以下注册表项:
    • HKEY_CURRENT_USER\Software\Embarcadero\Locales ("%TEMPDIR%\%executed_sample%": "en")
    • HKEY_CURRENT_USER\Software\Embarcadero\Locales
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications ("MaxSize": "1048576")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications ("Retention": "0")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Mechanic
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Service Manager
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Shield
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\ActiveCare
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Search and Recover
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\DriveScrubber
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Installer
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\System Guard
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Launch Manager
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Tune-Up Definitions
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Governor
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic ("EventMessageFile": "%APPDATA%\Roaming\iolo\EventMsg.dll")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic ("TypesSupported": "7")
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\iolo Applications\Memory Mechanic

将可疑文件/URL 送予我们分析,帮助构建更加安全的网站。

提交您的文件/URL 或者 转到 Avira 疑难解答

为何提交可疑文件?

如果您遇到不在我们数据库中的可疑文件或网站,我们将对其进行分析,确定其是否有害。我们的分析结果将惠及数百万用户,并将纳入下一次病毒数据库更新。如果您已经拥有 Avira,则会获取此更新。尚未拥有 Avira? 请前往 获取

什么是 Avira 疑难解答?

这是我们大力发展的社区,由专业技术人员和兼职专家通力合作,为广大用户解决技术问题。这一 Avira 用户社群是提出问题的绝佳场所。