BIOBOT.EXE – Backdoor Bifrose

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

BIOBOT.EXE – Backdoor Bifrose removal

FileMD5Virus Alias
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Backdoor Bifrose
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Trojan SuspiciousFile
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Trojan Generic
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Trojan Eldorado
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Backdoor RBot
BIOBOT.EXE e164e0458c4a001150b7be27cbd8275f Trojan Agent

BIOBOT.EXE size: 790528 bytes
BIOBOT.EXE hash: E164E0458C4A001150B7BE27CBD8275F

Created files:

%TEMP%\IXP000.TMP\14BOOT~1.EXE
%TEMP%\IXP000.TMP\BioBot.exe

Autostart registry keys:

HKLM\Software\Classes\CLSID\{AAC09E81-936B-7F4F-3256-424B5DA0856B}\InprocServer32 : adsnt.dll
HKLM\Software\Classes\CLSID\{AAC09E81-936B-7F4F-3256-424B5DA0856B}\InprocServer32\ThreadingModel: Both
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

BIOBOT.EXE
Default location: %TEMP%\IXP000.TMP\BIOBOT.EXE

Dropper information:
MD5: 5ad7e65083e2d14b2d97ef6e4c80200c
File size: 678400 bytes

Leave a Reply