Backdoor IRCBot – DesktopLayer.exe – 483cacdd03f9ac0c16a185e785e01387

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor IRCBot
Also known as: Trojan Generic
SHA256: 2718352baab223e495e7e739121de57d72547e4b978587fcdc5bf70d80e718cf
SHA1: d02ca00b7a5f75bcfee97cc00cb4e3b3eed5de72
MD5: 483cacdd03f9ac0c16a185e785e01387
File size: 628806 bytes

Created files:

%Program Files%\Microsoft\DesktopLayer.exe – Backdoor IRCBot
%Common AppData%\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe – Backdoor IRCBot
%Local AppData%\Google\Chrome\Application\17.0.963.56\avcodec-53.dll – Backdoor IRCBot
%Local AppData%\Google\Chrome\Application\17.0.963.56\avformat-53.dll – Backdoor IRCBot
%Local AppData%\Google\Chrome\Application\17.0.963.56\avutil-51.dll – Backdoor IRCBot

Backdoor IRCBot created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: c:\windows\System32\userinit.exe,,c:\program files\Microsoft\desktoplayer.exe

Leave a Reply