NETWORK SETUP WIZARD.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NETWORK SETUP WIZARD.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
NETWORK SETUP WIZARD.EXE e313e2c7909b0f5e0cf6be414e61d40b Backdoor IRCBot
NETWORK SETUP WIZARD.EXE e313e2c7909b0f5e0cf6be414e61d40b Backdoor Maximus
NETWORK SETUP WIZARD.EXE e313e2c7909b0f5e0cf6be414e61d40b Trojan Delphi
NETWORK SETUP WIZARD.EXE e313e2c7909b0f5e0cf6be414e61d40b Trojan Delf

NETWORK SETUP WIZARD.EXE size: 704828 bytes
NETWORK SETUP WIZARD.EXE hash: E313E2C7909B0F5E0CF6BE414E61D40B

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

NETWORK SETUP WIZARD.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\NETWORK SETUP WIZARD.EXE

Dropper information:
MD5: 083fb677cf7e4b5135ac25a2b8b8e678
File size: 653762 bytes

Leave a Reply