PokerStarsUninstall.exe

PokerStars Uninstall

PokerStars

The executable PokerStarsUninstall.exe has been detected as malware by 12 anti-virus scanners. This is the uninstaller utility registered in the Windows Control Panel for the program PokerStars.eu by PokerStars.eu. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
PokerStars

Product:
PokerStars Uninstall

Version:
1, 1, 0, 1

MD5:
30822d0326f371bf30d0ab42be16401a

SHA-1:
fdd9675220059b2399706e562342d924791c8d40

SHA-256:
698ca02ca0e0e8be79d585c223d481c157965eeccd3612e22c2e4747b2664a87

Scanner detections:
12 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 6:55:17 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5691347

avast!
Win32:Kukacka
160201-0

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5053.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
46826

File size:
447 KB (457,728 bytes)

Product version:
1, 1, 0, 0

Copyright:
Copyright © 2007-2015 PokerStars

Original file name:
PokerStarsUninstall.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\pokerstars.eu\pokerstarsuninstall.exe

File PE Metadata
Compilation timestamp:
12/3/2015 9:36:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:kvGJEN8fIOwS/Z65gHYpMvp2FYZTUtNjA4Hp3PgaOs1d4CT9nB:SGs2pwQZeUMI2FYV+BPgaDdVB

Entry address:
0x225B8

Entry point:
60, EB, 05, 15, CD, FE, 2A, B2, 08, EB, F6, C0, 52, 3D, 2D, AD, 5F, 6F, 8D, 05, A3, 5B, AC, B8, B5, 40, 0A, F9, 89, CB, 33, C2, 51, 68, B8, 73, 7B, 00, EB, 02, 87, D7, E8, 34, 00, 00, 00, 05, 9B, 4D, DC, 10, 87, F1, 81, FB, 0E, A5, 00, 00, 73, 08, 8D, 3D, FA, 5F, 52, 5C, 8A, F3, 0F, BE, F4, 41, BD, 00, 00, 00, 00, 8D, 0D, CC, A7, AB, ED, FE, CB, 03, E8, BE, 67, 38, E1, 82, 0F, AF, C8, 87, D8, 47, F2, F7, C1, 71, 06, 13, 19, 80, D0, CC, B6, D9, 88, E1, 3B, EB, BB, 00, 00, 00, 00, B1, 7E, 01, C7, 03, C2, F2...
 
[+]

Entropy:
6.8427

Code size:
201.5 KB (206,336 bytes)

Program Uninstaller
Program name:
PokerStars.eu

Display publisher:
PokerStars.eu

Uninstall string:
"C:\Program Files\PokerStars.EU\PokerStarsUninstall.exe" /u:PokerStars.eu


Remove PokerStarsUninstall.exe - Powered by Reason Core Security