uninstall.exe

The executable uninstall.exe has been detected as malware by 14 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This is the uninstaller utility registered in the Windows Control Panel for the program DesktopEyes. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
c7094985f8de1ca5ac4c1904f473072c

SHA-1:
d206b75d9b05aa525cda69a73ae1f8a383448baf

SHA-256:
44f97863401dd71bd9d8eb453a0ada5841e848b9066bcc4738a4fe26d46bdd86

Scanner detections:
14 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 4:20:23 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
6489932

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
SaliCode
150101-1

AVG
Win32/Sality
2014.0.4253

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
9.0.0.4799

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.13.68

Kaspersky
Virus.Win32.Sality
15.0.0.543

Microsoft Security Essentials
Threat.Undefined
1.191.3639.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.09

VIPRE Antivirus
Threat.4758034
36694

File size:
128 KB (131,105 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\desktopeyes\uninstall.exe

File PE Metadata
Compilation timestamp:
7/1/2006 8:05:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:rreY8CwqDxkJwAI05sPoit0hB3XYJ0xSZjlvI8HYHVMu:fkIw92tWZIJW841Mu

Entry address:
0x3166

Entry point:
0F, AF, D5, 80, EB, 2B, 69, FD, 15, 80, A1, F2, 69, C3, 2D, E2, 3B, 39, 3B, CB, 57, 74, 02, 89, F0, 87, FE, 68, 75, F4, F3, 00, 68, 10, F5, AB, 00, F6, D6, E8, 00, 00, 00, 00, 88, E8, 85, C5, 81, FE, CD, 1E, 00, 00, 5A, 69, CA, 1B, 01, 83, 02, 30, E9, 4F, 75, 02, 8B, EF, F7, D7, 3D, F7, CD, 00, 00, 73, 02, F7, DE, 0F, AF, F0, 01, EE, 8B, FB, BE, 77, 21, 06, 00, 0B, FA, 81, F6, BF, 5B, 00, 00, EB, 04, 85, D9, 1B, FF, 81, F6, CA, 7F, 06, 00, F7, DF, 56, 85, FE, 5D, F7, C6, CE, C6, F9, 45, 81, ED, 02, 05, 00...
 
[+]

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
DesktopEyes

Uninstall string:
"C:\Program Files\DesktopEyes\uninstall.exe"


Remove uninstall.exe - Powered by Reason Core Security