Quote:
The embedded IRC client uses a well known (and legitimate) IRC client library SmartIrc4net. The binary has some commands embedded as well, which can help distinguish what it can do:
.connect
.close
.stop
.hide
.show
.update
.version
.refresh
.platform
.memory
.cpu
.login
Finally, it can retrieve a remote file and save it on the local machine as TmpUpdateFile.exe – certainly sounds fishy.
While at the moment it does not appear to do anything bad (it just connects to the IRC server and sites there – there also appeared to be around 1000 machines running this when I tested this) the owner can probably do whatever he wants with machines running this.
The uninstall process seems to be correct, as the author(s) say on the web page, but it is questionable if the binary will download something else.
In any case, and as always – be careful what you download and run on your machine, especially if it's coming from unknown sources that you can't trust.