Backdoor IRCBot – sttemp939636340.bat – 1f32432c34955b6279cd715fa3567ae4

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor IRCBot
Also known as: Trojan Downloader.Generic, Trojan Generic
SHA256: 3644bb4b0c756f97f66ba133a50b4d7182b4453ffb17773ef3179ed6d8e1e35d
SHA1: ae17d4600230f07be6b38481444986b3b0c89181
MD5: 1f32432c34955b6279cd715fa3567ae4
File size: 182438 bytes

Created files:

C:\Windows\Temp\sttemp939636340.bat – Backdoor IRCBot
%AppData%\A939636340.exe – Backdoor IRCBot
%Startup%\A939636340.exe – Backdoor IRCBot

Backdoor IRCBot created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\A939636340: %AppData%\A939636340.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\A939636340: %AppData%\A939636340.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\A939636340: %AppData%\A939636340.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\A939636340: %AppData%\A939636340.exe

Leave a Reply