DEINSTALLER.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DEINSTALLER.EXE – Backdoor IRCBot removal

File MD5 Virus Alias
DEINSTALLER.EXE 94a3540a37b972a80f22c25f9b334e0d Backdoor IRCBot
DEINSTALLER.EXE 94a3540a37b972a80f22c25f9b334e0d Trojan Bitcoin
DEINSTALLER.EXE 94a3540a37b972a80f22c25f9b334e0d Trojan Btcmine
DEINSTALLER.EXE 94a3540a37b972a80f22c25f9b334e0d Trojan Xema
DEINSTALLER.EXE 94a3540a37b972a80f22c25f9b334e0d Trojan Downloader

DEINSTALLER.EXE size: 1253504 bytes
DEINSTALLER.EXE hash: 94A3540A37B972A80F22C25F9B334E0D

Created files:

%Program Files%\Ads Clever\deinstaller.exe
%Program Files%\Ads Clever\Installer.exe
%Program Files%\Ads Clever\lua5.1.dll
%Program Files%\Ads Clever\mpir.dll
%Program Files%\Ads Clever\msvcp100.dll
%Program Files%\Ads Clever\msvcr100.dll
%Program Files%\Ads Clever\OpenCL.dll
%Program Files%\Ads Clever\ProcessUsage.exe
%Program Files%\Ads Clever\uninstall.exe
%Program Files%\Ads Clever\VideoUsage.exe
%Temp%\_ir_sf_temp_0\lua5.1.dll

Detected by UnHackMe:

DEINSTALLER.EXE
Default location: %PROGRAM FILES%\ADS CLEVER\DEINSTALLER.EXE

Dropper information:
MD5: 0541d1ece63b5e051772c04c29943b91
File size: 6357032 bytes

Leave a Reply