PANDAViewer

Threat Scorecard

Ranking: 6,611
Threat Level: 10 % (Normal)
Infected Computers: 52,823
First Seen: April 6, 2017
Last Seen: September 21, 2023
OS(es) Affected: Windows

PANDAViewer is a software that you may find on free application distribution platforms or attached to free media plays as an optional offer. The PANDAViewer program has an official site at hxxp://www.pandaviewer[.]com where you might notice a logo saying 'Pview.' The PANDAViewer software is listed as a product by Banana Summer Technology Inc, which does not appear to have a standalone site and a LinkedIn listing. The download link for PANDAViewer points to hxxps://dz801hzlgfirn.cloudfront[.]net/panda/PandaViewer.exe and downloads a file with MD5:1fcc4f09ef7bc71bdd0b45c20a35264c1fc. The installer drops files to C:\Program Files (x86)\PandaViewer and may ask the user to reboot Windows.

You should know that PANDAViewer may install a browser add-on in Mozilla Firefox, Google Chrome, and Internet Explorer, which can be used by Banana Summer Technology Inc to monetize your Internet activity. The PANDAViewer application may collect information regarding the sites you explore and the content you download. Lab tests showed that PANDAViewer includes a software certificate from Shenzhen Zhongxiao Trading Co., Ltd. (a.k.a. Nayun Online Network Technology (Shenzhen) Co.Ltd.) that is associated with various ad-supported tools such as 'CornerSunshine', 'The Desktop Weather' and 'VSnapshotTool.' Installing PANDAViewer may lead to browser redirects and new tabs being opened in the background while you are surfing the Internet. Also, the PANDAViewer program was found to register a top-level exception handler, which may be used as an anti-debugging trick. PANDAViewer is known to change the user's browser settings and make Search.pandaviewer.com the default new tab page. The change may be enforced as a way to monetize your search operations and allow Banana Summer Technology Inc to earn money. You can find the EULA and Privacy Policy for PANDAViewer at hxxp://www.pandaviewer[.]com/eula and hxxp://www.pandaviewer[.]com/policy. PANDAViewer is deemed as a Potentially Unwanted Program (PUP) that you may want to remove. AV engines flag the files created by PANDAViewer as:

Artemis!1FCC4F09EF7B
BScope.Adware.AdAnti
Generic PUA LL (PUA)
Riskware ( 0052a9431 )
Riskware/Meterpreter
TROJ_GEN.R002C0DD618
Trojan.GenericKD.30552679
Trojan.Win32.Xadupi
Trojan.Win32.Z.Meterpreter
Unsafe.AI_Score_89%
W32/Trojan.SQMK-4853

SpyHunter Detects & Remove PANDAViewer

File System Details

PANDAViewer may create the following file(s):
# File Name MD5 Detections
1. panda_imageviewer.exe 13e19c0576f2188c022461a557208eab 1

Registry Details

PANDAViewer may create the following registry entry or registry entries:
File name without path
PandaViewer.lnk
pandaviewer[1].xml
SOFTWARE\Classes\PANDAViewer.bmp
SOFTWARE\Classes\PANDAViewer.gif
SOFTWARE\Classes\PandaViewer.ico
SOFTWARE\Classes\PANDAViewer.jpeg
SOFTWARE\Classes\PANDAViewer.jpg
SOFTWARE\Classes\PANDAViewer.png
SOFTWARE\Classes\PANDAViewer.tif
Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pandaviewer.com
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids\PANDAViewer.bmp
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids\PANDAViewer.gif
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids\PandaViewer.ico
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids\PANDAViewer.jpg
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\PANDAViewer.jpg
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\PANDAViewer.jpg
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids\PANDAViewer.png
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids\PANDAViewer.tif
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids\PANDAViewer.tif
SOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\PANDAViewer.jpg_.jpg
SOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\PANDAViewer.png_.png
SOFTWARE\Wow6432Node\PandaViewer

Directories

PANDAViewer may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\PandaViewer
%PROGRAMFILES%\PandaViewer
%PROGRAMFILES(x86)%\PandaViewer
%TEMP%\PandaViewer

Related Posts

Trending

Most Viewed

Loading...