Trojan Generic – IBBar.dll – 3fcad1bd2e78f9c469314e99c58f8338

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Generic
Also known as: Trojan Siggen, Trojan Downloader.Generic
SHA256: b153107b29245a06e4c96d5b746c81af263965f085666fb6c37dc1b11ed4a80d
SHA1: 0f73e7ca686aee6f685006cb79e8d1da1d8cbf61
MD5: 3fcad1bd2e78f9c469314e99c58f8338
File size: 995375 bytes

Created files:

%Program Files%\Instant Buzz\IBBar.dll – Trojan Generic
%Program Files%\Instant Buzz\IBDaemon.exe – Trojan Generic
%Program Files%\Instant Buzz\IBMH.dll – Trojan Generic
%Program Files%\Instant Buzz\IBSetup.exe – Trojan Generic

Trojan Generic created autostart registry keys:

HKLM\Software\Classes\CLSID\{7475D3FD-5D85-49DB-8B9B-6968467B2D80}\InprocServer32 : C:\PROGRA~1\INSTAN~1\IBBar.dll
HKLM\Software\Classes\CLSID\{7475D3FD-5D85-49DB-8B9B-6968467B2D80}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Classes\CLSID\{B8D60EBB-5565-4392-957B-7164BA087AD4}\InprocServer32 : C:\PROGRA~1\INSTAN~1\IBBar.dll
HKLM\Software\Classes\CLSID\{B8D60EBB-5565-4392-957B-7164BA087AD4}\InprocServer32\ThreadingModel: Apartment
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Instant Buzz Daemon: %Program Files%\Instant Buzz\IBDaemon.exe
HKLM\System\CurrentControlSet\Services\mchInjDrv\Type: 01000000
HKLM\System\CurrentControlSet\Services\mchInjDrv\Start: 04000000
HKLM\System\CurrentControlSet\Services\mchInjDrv\ImagePath: \??\%Temp%\mc26F.tmp
HKLM\System\CurrentControlSet\Services\mchInjDrv\DeleteFlag: 01000000

Leave a Reply