Backdoor IRCBot – p1308.exe – 681d635cb9fc5b2cdcef4c6ecd42281b

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor IRCBot
Also known as: Trojan Lethic, Trojan Jorik
SHA256: 0f4f62eca3a014a31f1c977611c9dce9bbd2498a0a4299b19e19a6b8a641d0f1
SHA1: 01ae78ae77a0ff1ba94e995b12ba74d1a8b30d4b
MD5: 681d635cb9fc5b2cdcef4c6ecd42281b
File size: 40960 bytes

Created files:

C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3668\p1308.exe – Backdoor IRCBot

Backdoor IRCBot created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3668\p1308.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\p1307: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3668\p1308.exe
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3668\p1308.exe

Leave a Reply