Backdoor IRCBot – sttemp939636340.bat – 7f8e5aec7a3a0b125dc178bde1b19511

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor IRCBot
Also known as: Trojan Generic, Trojan Downloader.Generic
SHA256: f198ae4f5352064c2db72a38c3aa48719d6518c03364dd95c01f71faf8df898b
SHA1: 81ec9054e4119cea28ce6dfbde2cf68b886099a9
MD5: 7f8e5aec7a3a0b125dc178bde1b19511
File size: 180931 bytes

Created files:

C:\Windows\Temp\sttemp939636340.bat – Backdoor IRCBot
%AppData%\A939636340.exe – Backdoor IRCBot
%Startup%\A939636340.exe – Backdoor IRCBot

Backdoor IRCBot created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\A939636340: %AppData%\A939636340.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\A939636340: %AppData%\A939636340.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\A939636340: %AppData%\A939636340.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\A939636340: %AppData%\A939636340.exe

Leave a Reply