OPERA_1161_INT_SETUP.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

OPERA_1161_INT_SETUP.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
OPERA_1161_INT_SETUP.EXE 0879c8f5d695b2162d78da5cd6da3f7b Backdoor IRCBot
OPERA_1161_INT_SETUP.EXE 0879c8f5d695b2162d78da5cd6da3f7b Backdoor Maximus
OPERA_1161_INT_SETUP.EXE 0879c8f5d695b2162d78da5cd6da3f7b Trojan Delphi
OPERA_1161_INT_SETUP.EXE 0879c8f5d695b2162d78da5cd6da3f7b Trojan Delf

OPERA_1161_INT_SETUP.EXE size: 717491 bytes
OPERA_1161_INT_SETUP.EXE hash: 0879C8F5D695B2162D78DA5CD6DA3F7B

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

OPERA_1161_INT_SETUP.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\OPERA_1161_INT_SETUP.EXE

Dropper information:
MD5: 0879c8f5d695b2162d78da5cd6da3f7b
File size: 717491 bytes

Leave a Reply