SAFARISETUP.EXE – Backdoor IRCBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SAFARISETUP.EXE – Backdoor IRCBot removal

FileMD5Virus Alias
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Backdoor IRCBot
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Trojan Hlux
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Trojan SuspiciousFile
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Trojan Eldorado
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Backdoor Maximus
SAFARISETUP.EXE 57f3b3300d57450af1b182649afeb719 Trojan Agent

SAFARISETUP.EXE size: 1877726 bytes
SAFARISETUP.EXE hash: 57F3B3300D57450AF1B182649AFEB719

Created files:

%SysDir%\sIRC4.exe
%SysDir%\xdccPrograms\Network Setup Wizard.exe
%SysDir%\xdccPrograms\Opera_1161_int_Setup.exe
%SysDir%\xdccPrograms\SafariSetup.exe
%SysDir%\xdccPrograms\Wireless Network Setup Wizard.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe sIRC4.exe

Detected by UnHackMe:

SAFARISETUP.EXE
Default location: %SYSDIR%\XDCCPROGRAMS\SAFARISETUP.EXE

Dropper information:
MD5: 999a35068ea65a789040b3f04555c56a
File size: 1877726 bytes

Leave a Reply