NETWORK SETUP WIZARD.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NETWORK SETUP WIZARD.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
NETWORK SETUP WIZARD.EXE 4cb069461b350be0f5a057f31bda15f0 Backdoor IRCBot
NETWORK SETUP WIZARD.EXE 4cb069461b350be0f5a057f31bda15f0 Backdoor Maximus
NETWORK SETUP WIZARD.EXE 4cb069461b350be0f5a057f31bda15f0 Trojan Delphi
NETWORK SETUP WIZARD.EXE 4cb069461b350be0f5a057f31bda15f0 Trojan Delf

NETWORK SETUP WIZARD.EXE size: 180307 bytes
NETWORK SETUP WIZARD.EXE hash: 4CB069461B350BE0F5A057F31BDA15F0

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

NETWORK SETUP WIZARD.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\NETWORK SETUP WIZARD.EXE

Dropper information:
MD5: 0a9d0a7cbfe76cbc624d9f5d34ec8a6e
File size: 149562 bytes

Leave a Reply