PUA.Win32.FusionCore.SMBD
W32/FusionCore.A.gen!Eldorado (FPROT); a variant of Win32/FusionCore.L potentially unwanted application (NOD32)
Windows

Threat Type: Potentially Unwanted Application
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
1,063,424 bytes
EXE
No
04 Oct 2019
Arrival Details
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Potentially Unwanted Application drops the following files:
- %Program Files%\Rene.E Laboratory\PDFAide\unins000.exe
- %Program Files%\Rene.E Laboratory\PDFAide\msvcp100.dll
- %Program Files%\Rene.E Laboratory\PDFAide\msvcr100.dll
- %Program Files%\Rene.E Laboratory\PDFAide\QtCore4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\QtGui4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\QtNetwork4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\QtWebKit4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\QtXml4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\RsCrashRestarter.exe
- %Program Files%\Rene.E Laboratory\PDFAide\vcredist_x86.exe
- %Program Files%\Rene.E Laboratory\PDFAide\cmap\cmap_cns.dll
- %Program Files%\Rene.E Laboratory\PDFAide\cmap\cmap_gb.dll
- %Program Files%\Rene.E Laboratory\PDFAide\cmap\cmap_japan.dll
- %Program Files%\Rene.E Laboratory\PDFAide\cmap\cmap_korea.dll
- %Program Files%\Rene.E Laboratory\PDFAide\imageformats\qgif4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\imageformats\qjpeg4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\imageformats\qtiff4.dll
- %Program Files%\Rene.E Laboratory\PDFAide\sample\chi_sim_text.jpg
- %Program Files%\Rene.E Laboratory\PDFAide\sample\chi_tra_text.jpg
- %Program Files%\Rene.E Laboratory\PDFAide\sample\eng_text.jpg
- %Program Files%\Rene.E Laboratory\PDFAide\sample\jap_text.jpg
- %Program Files%\Rene.E Laboratory\PDFAide\sample\kor_text.jpg
- %Program Files%\Rene.E Laboratory\PDFAide\sample\link_test.pdf
- %Program Files%\Rene.E Laboratory\PDFAide\sample\Pdf2Office.pdf
- %Program Files%\Rene.E Laboratory\PDFAide\watermark\watermark_chn.pdf
- %Program Files%\Rene.E Laboratory\PDFAide\watermark\watermark_kor.pdf
- %Program Files%\Rene.E Laboratory\PDFAide\libeay32.dll
- %Program Files%\Rene.E Laboratory\PDFAide\ocrconfig.dat
- %Program Files%\Rene.E Laboratory\PDFAide\PdfAide.exe
- %Program Files%\Rene.E Laboratory\PDFAide\ReFB.exe
- %Program Files%\Rene.E Laboratory\PDFAide\ReneeUpdater.exe
- %Program Files%\Rene.E Laboratory\PDFAide\ReTW.exe
- %Program Files%\Rene.E Laboratory\PDFAide\ssleay32.dll
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).)
It adds the following processes:
- "%Program Files%\Rene.E Laboratory\PDFAide\vcredist_x86.exe" /norestart /q
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).)
It creates the following folders:
- %Program Files%\Rene.E Laboratory
- %Program Files%\Rene.E Laboratory\PDFAide\imageformats
- %Program Files%\Rene.E Laboratory\PDFAide
- %Program Files%\Rene.E Laboratory\PDFAide\watermark
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Rene.E Laboratory\PDFAide
- %Program Files%\Rene.E Laboratory\PDFAide\cmap
- %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Rene.E Laboratory
- %Program Files%\Rene.E Laboratory\PDFAide\sample
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %All Users Profile% is the common user's profile folder, which is usually C:\Documents and Settings\All Users on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\ProgramData on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit). )
Other System Modifications
This Potentially Unwanted Application adds the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults
It adds the following registry entries:
HKEY_CURRENT_USER\Software\Rene.E Laboratory\
PDFAide
iProgramLanguage = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Inno Setup: Setup Version = "5.5.4 (u)"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Inno Setup: App Path = "%Program Files%\Rene.E Laboratory\PDFAide"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
InstallLocation = "%Program Files%\Rene.E Laboratory\PDFAide"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Inno Setup: Icon Group = "Rene.E Laboratory\PDFAide"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Inno Setup: User = "{username}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Inno Setup: Language = "en"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
DisplayName = "Renee PDF Aide 2016.10.13.71"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
UninstallString = "%Program Files%\Rene.E Laboratory\PDFAide\unins000.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
QuietUninstallString = "%Program Files%\Rene.E Laboratory\PDFAide\unins000.exe /SILENT"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
DisplayVersion = "2016.10.13.71"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
Publisher = "Rene.E Laboratory"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
URLInfoAbout = "http://www.{BLOCKED}ab.com"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
HelpLink = "http://www.{BLOCKED}ab.com"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
URLUpdateInfo = "http://www.{BLOCKED}ab.com"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
NoModify = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
NoRepair = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
InstallDate = "{date}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
MajorVersion = "2016"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
MinorVersion = "10"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{GUID}_is1
EstimatedSize = "52030"
HKEY_CURRENT_USER\Software\Rene.E Laboratory
JoinOperationShare = "1"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Plugin Cache 4.8.false\%Program Files%\
Rene.E Laboratory\PDFAide\imageformats
qgif4.dll = "\x00\x00\x00\x00"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\
%Program Files%\Rene.E Laboratory\PDFAide\
imageformats
qgif4.dll = "\x00\x00"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Plugin Cache 4.8.false\%Program Files%\
Rene.E Laboratory\PDFAide\imageformats
qjpeg4.dll = "\x00\x00\x00\x00"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\
%Program Files%\Rene.E Laboratory\PDFAide\
imageformats
qjpeg4.dll = "\x00\x00\x00"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Plugin Cache 4.8.false\%Program Files%\
Rene.E Laboratory\PDFAide\imageformats
qtiff4.dll = "\x00\x00\x00\x00"
HKEY_CURRENT_USER\Software\Trolltech\
OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\
%Program Files%\Rene.E Laboratory\PDFAide\
imageformats
qtiff4.dll = "\x00\x00\x00"
HKEY_CURRENT_USER\Software\Rene.E Laboratory\
PDFAide
FreeVersionDaysEntry = "{hex data}"
Other Details
This Potentially Unwanted Application connects to the following possibly malicious URL:
- http://rp.{BLOCKED}uardapp.com/
- http://os.{BLOCKED}uardapp.com/FusionReneeLab/
- http://os2.{BLOCKED}uardapp.com/FusionReneeLab/
- http://os.{BLOCKED}uardapp.com/FusionReneeLab/
SOLUTION
9.850
2.203.00
08 Aug 2019
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Remove PUA.Win32.FusionCore.SMBD by using its own Uninstall option
Step 3
Scan your computer with your Trend Micro product to delete files detected as PUA.Win32.FusionCore.SMBD. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.