registryquick.exe

The application registryquick.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RegistryQuick.exe’. While running, it connects to the Internet address apache2-emu.thomas-heyward-jr.dreamhost.com on port 80 using the HTTP protocol.
MD5:
7ba9b85755b8dd4e791ad62947d11bee

SHA-1:
d33162c416969d331484ac73e97eac78225743bf

SHA-256:
c4da7ec9d1378340dcb6d11f8899920432497a78653cd2e1eed07a52fa000912

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 4:43:38 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
140908-2

AVG
Trojan horse SHeur4.XAM
2014.0.4015

Baidu Antivirus
Adware.Win32.RegistryQuick
4.0.3.14917

Bkav FE
W32.Clodfdf.Trojan
1.3.0.4959

ESET NOD32
Win32/Adware.RegistryQuick application
7.0.302.0

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.7.8.0

NANO AntiVirus
Riskware.Win32.RegistryQuick.cvvpcp
0.28.2.62151

VIPRE Antivirus
Threat.4150696
32938

File size:
3.8 MB (4,019,712 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\requick\registryquick.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:zm5p3WDlODG6Q4k1czhP/fpuQArxc/wHEb:zm5p3+lSG6hrz6QKxcq

Entry address:
0x135120

Entry point:
55, 8B, EC, 83, C4, E0, 53, 33, C0, 89, 45, E4, 89, 45, E0, 89, 45, E8, 89, 45, EC, B8, 40, 4A, 53, 00, E8, C5, 14, ED, FF, 33, C0, 55, 68, D1, 53, 53, 00, 64, FF, 30, 64, 89, 20, A1, 08, AB, 53, 00, 8B, 00, E8, 2B, B8, F5, FF, A1, 08, AB, 53, 00, 8B, 00, BA, E8, 53, 53, 00, E8, 12, B4, F5, FF, E8, AD, 72, F7, FF, A1, 10, A8, 53, 00, 83, 38, 06, 0F, 8C, C1, 00, 00, 00, E8, 3E, 87, F7, FF, 84, C0, 0F, 85, B4, 00, 00, 00, E8, 55, 86, F7, FF, 84, C0, 0F, 84, A7, 00, 00, 00, B2, 01, A1, AC, 0E, 44, 00, E8, 09...
 
[+]

Entropy:
6.4312

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,263,104 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RegistryQuick.exe

Command:
C:\Program Files\requick\registryquick.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to apache2-emu.thomas-heyward-jr.dreamhost.com  (208.97.177.11:80)

Remove registryquick.exe - Powered by Reason Core Security