NETWORK SETUP WIZARD.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NETWORK SETUP WIZARD.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
NETWORK SETUP WIZARD.EXE 1bf132229c1da8a3de4a2d58e7f28a1f Backdoor IRCBot
NETWORK SETUP WIZARD.EXE 1bf132229c1da8a3de4a2d58e7f28a1f Backdoor Maximus
NETWORK SETUP WIZARD.EXE 1bf132229c1da8a3de4a2d58e7f28a1f Trojan Delphi
NETWORK SETUP WIZARD.EXE 1bf132229c1da8a3de4a2d58e7f28a1f Trojan Delf

NETWORK SETUP WIZARD.EXE size: 728791 bytes
NETWORK SETUP WIZARD.EXE hash: 1BF132229C1DA8A3DE4A2D58E7F28A1F

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

NETWORK SETUP WIZARD.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\NETWORK SETUP WIZARD.EXE

Dropper information:
MD5: 0879c8f5d695b2162d78da5cd6da3f7b
File size: 717491 bytes

Leave a Reply