Home / Spyware Encyclopedia / IM.BadBoy << Back

Recommendation to Automatically remove IM.BadBoy


Our products can remove IM.BadBoy and thousands of other Virus and Spyware automatically and instantly.

IM.BadBoy Details


  • Category IM
  • Discovered 10/22/2013 7:53:24 AM
  • Modified 6/25/2020 12:12:20 PM
  • Threat Level Critical
  • Category Description
    A threat that is capable to cause Denial-Of-Service attacks against other instant messenger client systems.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
ntlcss.exe 59813rajeh1.0.0.032e20e477c1092fa86ec3a693daf16e5 
Trojan-Dropper.Win32.Small.abe.dll 352256 1.0.0.15300f1d290dff19b038db935d75fd8c4 
Trojan-Dropper.Win32.Small.abh.exe 28160  f1c477e7218f067709a672556b7446ab 
perfcl.exe 200704  d122387d926ea2b6cace057d5a95ac6f 
w11150.exe 146518  bf7710a070b2b9348799c0b6e7633ff5 
Trojan-Dropper.Win32.Small.abs.exe 187392  aa4d3337d7a3c4848d8a55af62322cf6 
Trojan-Dropper.Win32.Small.abm.exe 7777  9e42312629a3650e8116ad1aa9a366df 
Trojan-Dropper.Win32.Small.abi.exe 9216  9a02791088ee94e856e79d5a05e4b9f3 
webrebates.exe 368368  32e596d47810b30e355f7033ffa9438c 
webrebates.dll 102400  2c418f2e635a1072dd34a7107a77c4e0 

The following Registry Entries were created:
..\Software\local appwizard-generated applications\Help_me\(Default)
..\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\"SvcSys"\"{ECD59ADC-677F-46A0-AD72-B65A512EBE8A}"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"WebRebates0"\"%PF%\Web_Rebates\WebRebates0.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"PerformCl"\"%DAS.AU.LS%\Temp\perfcl.exe"
..\Software\Classes\Clsid\{ECD59ADC-677F-46A0-AD72-B65A512EBE8A}\(Default)
..\Software\Microsoft\Windows\CurrentVersion\Run\\"webrebates"\""%PF%\WebRebates4\webrebates.exe""
..\Software\Microsoft\Internet Explorer\Toolbar\\"CLSID"\"{B75F75B8-93F3-429D-FF34-660B206D897A}"
..\Software\Microsoft\ACTIVE SETUP\INSTALLED COMPONENTS\{5Y99AE78-58TT-11DW-BE53-Y67078979Y}\(Default)
..\Software\zsearchco\(Default)
..\Software\Classes\ztoolbar.stockbar.1\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware