NETWORK SETUP WIZARD.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NETWORK SETUP WIZARD.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
NETWORK SETUP WIZARD.EXE 116171a4293a6321fd43b7b5894825c3 Backdoor IRCBot
NETWORK SETUP WIZARD.EXE 116171a4293a6321fd43b7b5894825c3 Backdoor Maximus
NETWORK SETUP WIZARD.EXE 116171a4293a6321fd43b7b5894825c3 Trojan Delphi
NETWORK SETUP WIZARD.EXE 116171a4293a6321fd43b7b5894825c3 Trojan Delf

NETWORK SETUP WIZARD.EXE size: 930654 bytes
NETWORK SETUP WIZARD.EXE hash: 116171A4293A6321FD43B7B5894825C3

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

NETWORK SETUP WIZARD.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\NETWORK SETUP WIZARD.EXE

Dropper information:
MD5: 116171a4293a6321fd43b7b5894825c3
File size: 930654 bytes

Leave a Reply