DEINSTALLER.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DEINSTALLER.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
DEINSTALLER.EXE a2ca43bb779a70f7d3196ab4714eff4a Backdoor IRCBot
DEINSTALLER.EXE a2ca43bb779a70f7d3196ab4714eff4a Trojan Bitcoin
DEINSTALLER.EXE a2ca43bb779a70f7d3196ab4714eff4a Trojan XPACK
DEINSTALLER.EXE a2ca43bb779a70f7d3196ab4714eff4a Trojan CoinMiner

DEINSTALLER.EXE size: 1255008 bytes
DEINSTALLER.EXE hash: A2CA43BB779A70F7D3196AB4714EFF4A

Created files:

%Program Files%\Windows Codec Pack\deinstaller.exe
%Program Files%\Windows Codec Pack\Installer.exe
%Program Files%\Windows Codec Pack\lua5.1.dll
%Program Files%\Windows Codec Pack\plg0.dll
%Program Files%\Windows Codec Pack\plg1.dll
%Program Files%\Windows Codec Pack\Traymonitor.exe
%Program Files%\Windows Codec Pack\uninstall.exe
%TEMP%\_ir_sf_temp_0\lua5.1.dll

Detected by UnHackMe:

DEINSTALLER.EXE
Default location: %PROGRAM FILES%\WINDOWS CODEC PACK\DEINSTALLER.EXE

Dropper information:
MD5: 46d02ebc87bc17ddc12dd1aa606c9a77
File size: 7557920 bytes

Leave a Reply