Backdoor

Backdoor.Ircbot.ADLM removal instruction

Malware Removal

The Backdoor.Ircbot.ADLM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Ircbot.ADLM virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

f.eastmoon.pl
s.richlab.pl
gigasbh.org
xixbh.com

How to determine Backdoor.Ircbot.ADLM?


File Info:

crc32: 78614900
md5: 6b1d0f6833699bcc9c43d838cb2a853a
name: 6B1D0F6833699BCC9C43D838CB2A853A.mlw
sha1: ed399d34c793afe95e0c918d92db4a1a3b078022
sha256: 451b6159f2d86e4efd9b1618f06bf97e02df3ef82cb4153eba75fd8908d06a03
sha512: 78e10288d5a9231342995ffc8e58275de54ffd0418fc01c2918818bf54b511416f0d206a2207c6cad86ed1a597cb71b4eddf53bb42c704b0891e72ed15b7e06c
ssdeep: 1536:XNp/otq+npH+7nRtCd8pOVpU3eWqr3BHmg2hu87YMMLBi1Cu82oBdK5DbVooo+Y:pUKnu5I/Gn2O7oCZ2vtoo1DCTf5BxXj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Ircbot.ADLM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Codex.5
CynetMalicious (score: 100)
ALYacBackdoor.Ircbot.ADLM
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.833699
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Nomkesh.C
APEXMalicious
AvastWin32:Dorkbot-CS [Wrm]
KasperskyTrojan-Ransom.Win32.Blocker.bajs
BitDefenderBackdoor.Ircbot.ADLM
NANO-AntivirusTrojan.Win32.Blocker.eyvegy
MicroWorld-eScanBackdoor.Ircbot.ADLM
TencentWin32.Trojan.Blocker.Wogj
Ad-AwareBackdoor.Ircbot.ADLM
SophosML/PE-A + Mal/Dorkbot-S
BitDefenderThetaAI:Packer.0AB127BE1C
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_DORKBOT.LV
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.6b1d0f6833699bcc
EmsisoftBackdoor.Ircbot.ADLM (B)
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.194BDA
GDataBackdoor.Ircbot.ADLM
AhnLab-V3Trojan/Win32.Blocker.C3441713
McAfeeGeneric.dpz
MAXmalware (ai score=99)
VBA32Hoax.Blocker
PandaGeneric Malware
TrendMicro-HouseCallWORM_DORKBOT.LV
RisingTrojan.Generic@ML.100 (RDML:0gImoQQKomxjPO3XAuOkhg)
YandexTrojan.GenAsa!K7RFnRhW690
SentinelOneStatic AI – Malicious PE
FortinetW32/Nomkesh.C!worm
AVGWin32:Dorkbot-CS [Wrm]
Paloaltogeneric.ml

How to remove Backdoor.Ircbot.ADLM?

Backdoor.Ircbot.ADLM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment