Jump to content

Windows Update Notification Tool (Backdoor.IRCBot)


Quppa

Recommended Posts

A couple of users have reported that Malwarebytes Anti-Malware detects my Windows Update Notification Tool as being infected with 'Backdoor.IRCBot'. I can't seem to reproduce this on my system with the latest version/definitions of MBAM, but here's a log from someone else:

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.15.11

Windows 8 x64 NTFS

Internet Explorer 10.0.9200.16580

*** :: *** [administrator]

2013-05-15 5:46:23 PM

mbam-log-2013-05-15 (17-46-23).txt

Scan type: Full scan (C:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 502108

Time elapsed: 51 minute(s), 9 second(s)

Memory Processes Detected: 1

C:\Program Files\Windows Update Notification Tool\WUNotify.exe (Backdoor.IRCBot) -> 3712 -> Delete on reboot.

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 1

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Windows Update Notification Tool (Backdoor.IRCBot) -> Data: C:\Program Files\Windows Update Notification Tool\WUNotify.exe -> Quarantined and deleted successfully.

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 1

C:\Program Files\Windows Update Notification Tool\WUNotify.exe (Backdoor.IRCBot) -> Delete on reboot.

(end)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.