PODCASTBARMINISTARTER.EXE – Trojan CI

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

PODCASTBARMINISTARTER.EXE – Trojan CI removal

FileMD5Virus Alias
PODCASTBARMINISTARTER.EXE c5a403de2bf20df4fc6219a83df35311 Trojan CI
PODCASTBARMINISTARTER.EXE c5a403de2bf20df4fc6219a83df35311 Trojan Agent

PODCASTBARMINISTARTER.EXE size: 139264 bytes

Created files:

%Program Files%\pcast\PodcastbarMini\pCastCtl.dll
%Program Files%\pcast\PodcastbarMini\PcastUpdate.dll
%Program Files%\pcast\PodcastbarMini\PodcastBarMini.exe
%Program Files%\pcast\PodcastbarMini\PodcastBarMiniObj.dll
%Program Files%\pcast\PodcastbarMini\PodcastBarMiniStarter.exe
%Program Files%\pcast\PodcastbarMini\uninst.exe

Autostart registry keys:

HKLM\Software\Classes\CLSID\{87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667}\InprocServer32 : %Program Files%\pcast\PodcastbarMini\PcastUpdate.dll
HKLM\Software\Classes\CLSID\{C1764EBE-FE4F-4F55-B826-89A8AA62A7E0}\InprocServer32 : %Program Files%\pcast\PodcastbarMini\PodcastBarMiniObj.dll
HKLM\Software\Classes\CLSID\{FEE1002D-90A5-4A5D-AABE-01803FFBCF7A}\InprocServer32 : %Program Files%\pcast\PodcastbarMini\pcastctl.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\pbmini: %Program Files%\pcast\PodcastbarMini\PodcastBarMiniStater.exe

Detected by UnHackMe:

PODCASTBARMINISTARTER.EXE
Default location: %PROGRAM FILES%\PCAST\PODCASTBARMINI\PODCASTBARMINISTARTER.EXE

Leave a Reply