Backdoor IRCBot – sIRC4.exe – 02dd4ee418e44854bc98b79d6b09a55d

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor IRCBot
Also known as: Trojan Delf, Trojan Delphi
SHA256: 8d830f76d2aa32d706f6c5418bb3c6c13413896f59b445cbbac5bd5e9151aa78
SHA1: a8a3d1518acd4c8aa1d869c030892d109d74e3bd
MD5: 02dd4ee418e44854bc98b79d6b09a55d
File size: 280648 bytes

Created files:

%SysDir%\sIRC4.exe – Backdoor IRCBot
%SysDir%\xdccPrograms\Network Setup Wizard.exe – Backdoor IRCBot
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe – Backdoor IRCBot
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe – Backdoor IRCBot

Backdoor IRCBot created autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Leave a Reply