XBINS.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

XBINS.EXE – Trojan Agent removal

FileMD5Virus Alias
XBINS.EXE 71b6d23abaef923396f2d81f80c5ccd4 Trojan Agent
XBINS.EXE 71b6d23abaef923396f2d81f80c5ccd4 Trojan SuspiciousFile
XBINS.EXE 71b6d23abaef923396f2d81f80c5ccd4 Trojan Generic
XBINS.EXE 71b6d23abaef923396f2d81f80c5ccd4 Backdoor IRCBot

XBINS.EXE size: 1050112 bytes
XBINS.EXE hash: 71B6D23ABAEF923396F2D81F80C5CCD4

Created files:

%SysDir%\Wind0ws32.exe
%TEMP%\IXP000.TMP\360FLA~1.EXE
%TEMP%\IXP000.TMP\xbins.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Wind0ws32.exe: C:\windows\System32\Wind0ws32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%TEMP%\IXP000.TMP\”

Detected by UnHackMe:

XBINS.EXE
Default location: %TEMP%\IXP000.TMP\XBINS.EXE

Dropper information:
MD5: 9acb4fc9104b576c228738f16c3ecec3
File size: 1199616 bytes

Leave a Reply