Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:Adware/InstallRex.Q
Type:Adware/Spyware
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
MD5 checksum:061ADF82EEA7BCD152B6F8CD5A425FCA

 General Methods of propagation:
   • No own spreading routine


Aliases:
   •  Kaspersky: not-a-virus:Downloader.Win32.AdLoad.fwz
   •  Eset: Win32/InstalleRex.L application
     DrWeb: Adware.Downware.1541


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


Side effects:
   • Downloads files

 Files The following files are created:

Non malicious files:
   • C:\TEMP\Tsu08B83444.dll
   • C:\TEMP\EAA19544.dat
   • C:\TEMP\{7B02DD58-2372-458F-A764-6B50A0E1FFAE}\_Setup.dll
   • C:\TEMP\{7B02DD58-2372-458F-A764-6B50A0E1FFAE}\Setup.ico
   • C:\TEMP\{7B02DD58-2372-458F-A764-6B50A0E1FFAE}\Custom.dll

C:\Temp\{7B02DD58-2372-458F-A764-6B50A0E1FFAE}\Addons\ext_setup.exe Furthermore it gets executed after it was fully created.
C:\TEMP\{7B02DD58-2372-458F-A764-6B50A0E1FFAE}\Setup.exe Furthermore it gets executed after it was fully created.

 Miscellaneous Accesses internet resources:
   • r1.**********ylezip.info; c1.**********lezip.info;
      **********wnloadmy.ru; dl.**********ers.net;
      bi.**********ers.net; dl.tus**********.net;
      world-down**********.info; ceterofcom**********.info;
      cybei**********.info

Description inserted by Jan-Eric Herting on Saturday, November 23, 2013
Description updated by Jan-Eric Herting on Saturday, November 23, 2013

Back . . . .