Home Malware Programs Backdoors Backdoor.IRCbot.FY

Backdoor.IRCbot.FY

Posted: May 28, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 1,211
First Seen: May 28, 2012
Last Seen: April 23, 2022
OS(es) Affected: Windows

Aliases

SHeur4.AACW [AVG]W32/Llac.SHV!tr [Fortinet]Dropper/Win32.Dapato [AhnLab-V3]BDS/IRCBot.FY.163 [AntiVir]TrojWare.Win32.Injector.tmw [Comodo]Win32.Kryptik.Aehq [eSafe]Win32:Crypt-MQL [Trj] [Avast]W32/Sdbot.worm!nf [McAfee]Dropper.Generic6.CJPC [AVG]W32/Injector.FYEK!tr [Fortinet]Trojan-Dropper.Win32.Dapato [Ikarus]BDS/IRCBot.FY.391 [AntiVir]Trojan.Packed.23326 [DrWeb]Troj/Agent-YIM [Sophos]Trojan-Dropper.Win32.Injector.fyek [Kaspersky]
More aliases (469)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\M-50-8964-7854-4678\winmgr.exe File name: winmgr.exe
Size: 112.12 KB (112128 bytes)
MD5: 0b97371ce63070b5ea6c68668f719c01
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-50-8964-7854-4678
Group: Malware file
Last Updated: October 8, 2012
%USERPROFILE%\P-7-78-8964-9648-3874\windll.exe File name: windll.exe
Size: 61.44 KB (61440 bytes)
MD5: 834787cc1e2d81d4967d8d420ad7ea2a
Detection count: 89
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: November 2, 2012
%USERPROFILE%\K-37763-383-2847-00\winsrc.exe File name: winsrc.exe
Size: 286.72 KB (286720 bytes)
MD5: 573837fb1499e34eaad94c329247ee67
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\K-37763-383-2847-00
Group: Malware file
Last Updated: December 24, 2012
%PROGRAMFILES%\Internet Explorer\ctfmonrod.exe File name: ctfmonrod.exe
Size: 11.26 KB (11264 bytes)
MD5: a0d53ea1a6157e972d109b61a67a2a0e
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Internet Explorer
Group: Malware file
Last Updated: June 8, 2012
%USERPROFILE%\M-10-356663-2978-3464\winmgr.exe File name: winmgr.exe
Size: 233.47 KB (233472 bytes)
MD5: d2d582abeb6248f541e5e616628ec479
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-10-356663-2978-3464
Group: Malware file
Last Updated: October 5, 2012
%USERPROFILE%\P-7-78-8964-9648-3874\winpvc.exe File name: winpvc.exe
Size: 122.88 KB (122880 bytes)
MD5: fb7a1d047edf9d5c9e816549d9e68ce6
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: January 8, 2013
%APPDATA%\55C6.exe File name: 55C6.exe
Size: 82.43 KB (82432 bytes)
MD5: aec8713df8b8bd3191ae96575bce0355
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 27, 2012
%APPDATA%\53B6.exe File name: 53B6.exe
Size: 82.43 KB (82432 bytes)
MD5: fd02fd2e07a762eddededb14feae1060
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 27, 2012
%APPDATA%\2FB4.exe File name: 2FB4.exe
Size: 83.45 KB (83456 bytes)
MD5: 51234eb868d4db068e1badf7a87ece31
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 27, 2012
%WINDIR%\system32\YKRXLC\TGN.exe File name: TGN.exe
Size: 1.78 MB (1789440 bytes)
MD5: 69654934ee989113a3ef7b852abf39f5
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\YKRXLC
Group: Malware file
Last Updated: May 31, 2012
%COMMONPROGRAMFILES%\BOONTY Shared\Service\Boonty.exe File name: Boonty.exe
Size: 69.12 KB (69120 bytes)
MD5: 22b8a8ec0ba19333ebe0635f09fa67f2
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\BOONTY Shared\Service
Group: Malware file
Last Updated: May 15, 2020
%APPDATA%\DA.exe File name: DA.exe
Size: 208.89 KB (208896 bytes)
MD5: 8eb63a73b6824d6b183855d5556dacef
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 7, 2012
%USERPROFILE%\16750187-0001-1100245\svcsrv.exe File name: svcsrv.exe
Size: 36.86 KB (36864 bytes)
MD5: 171f673d6abee68ac026d4af751b9c66
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\16750187-0001-1100245
Group: Malware file
Last Updated: August 6, 2012
%USERPROFILE%\P-7-78-8964-9648-3874\wincrs.exe File name: wincrs.exe
Size: 201.22 KB (201225 bytes)
MD5: f1d69fbf46c4e6c4b736d2045de96387
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: August 13, 2012
C:\Program Files (x86)\AdWare SpyWare Removal\AdWare SpyWare Removal.exe File name: AdWare SpyWare Removal.exe
Size: 3.78 MB (3789312 bytes)
MD5: 5bb8fdd7f6e1b24fbac9097277327a5e
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\AdWare SpyWare Removal\AdWare SpyWare Removal.exe
Group: Malware file
Last Updated: October 3, 2021
%USERPROFILE%\P-7-78-8964-9648-3874\windll.exe File name: windll.exe
Size: 85.89 KB (85892 bytes)
MD5: 61350e9013895b1dc89b3c6d1c0dbb6c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: August 6, 2012
C:\XXXXGAS\SHUTDOWN.EXE File name: SHUTDOWN.EXE
Size: 230.25 KB (230252 bytes)
MD5: 27cd93d7b24db6a659395159a61aa388
Detection count: 12
File type: Executable File
Mime Type: unknown/EXE
Path: C:\XXXXGAS\SHUTDOWN.EXE
Group: Malware file
Last Updated: April 23, 2022
%USERPROFILE%\M-87-78985-6027-77788\winsvcr.exe File name: winsvcr.exe
Size: 42.49 KB (42496 bytes)
MD5: f85836eeda47d9167fda7b67b4eb86a7
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-87-78985-6027-77788
Group: Malware file
Last Updated: October 12, 2012
%APPDATA%\SubeVisitas.exe File name: SubeVisitas.exe
Size: 53.24 KB (53248 bytes)
MD5: e0c87793e7f964b8b78d96448c501413
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 1, 2012
%WINDIR%\system32\agl23.exe File name: agl23.exe
Size: 802.81 KB (802816 bytes)
MD5: 717781bbf0430872b11d7f312965d5dc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 28, 2012
%USERPROFILE%\Mijn documenten\Downloads\Picture-392-album-10017.exe File name: Picture-392-album-10017.exe
Size: 32.76 KB (32768 bytes)
MD5: 9fed3ba3d60e6ff17d8ae72c2fdca867
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Mijn documenten\Downloads
Group: Malware file
Last Updated: December 5, 2012
%USERPROFILE%\P-7-78-8964-9648-3874\windll.exe File name: windll.exe
Size: 48.64 KB (48640 bytes)
MD5: 1e6644a4645bdaee3852784bb4f0c572
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: February 11, 2013
%USERPROFILE%\P-7-78-8964-9648-3874\windll.exe File name: windll.exe
Size: 64 KB (64000 bytes)
MD5: fb91cfe14d068aa8f8555ae4ac2c25ac
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\P-7-78-8964-9648-3874\wincrs.exe File name: wincrs.exe
Size: 29.18 KB (29184 bytes)
MD5: f207a41c8e5a793db634eb84e1c537fe
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: December 7, 2012

More files
Loading...