Solved! Use DMADMIN.VIR (Virus Expiro) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DMADMIN.VIR – Virus Expiro removal

File MD5 Virus Alias
DMADMIN.VIR b3ffb61c94542fa633f9a1bf5b30d38a Virus Expiro
DMADMIN.VIR b3ffb61c94542fa633f9a1bf5b30d38a Virus Pioneer

DMADMIN.VIR size: 388608 bytes
DMADMIN.VIR hash: B3FFB61C94542FA633F9A1BF5B30D38A

Created files:

%SysDir%\cisvc.vir
%SysDir%\clipsrv.vir
%SysDir%\dllhost.exe
%SysDir%\dmadmin.vir
%SysDir%\imapi.vir
%SysDir%\mnmsrvc.vir
%SysDir%\msdtc.vir
%SysDir%\msiexec.vir
%SysDir%\svchost.vir

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\msiserver\Type: 20010000
HKLM\System\CurrentControlSet\Services\msiserver\Start: 02000000
HKLM\System\CurrentControlSet\Services\msiserver\SBIE_CheckPoint: 01000000

Detected by UnHackMe:

DMADMIN.VIR
Default location: %SYSDIR%\DMADMIN.VIR

Dropper information:
MD5: 9b310129819ff9c61df52b3b36b9bd78
File size: 314368 bytes

Leave a Reply