Backdoor

What is “Backdoor.IRCBot.OLGen”?

Malware Removal

The Backdoor.IRCBot.OLGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.IRCBot.OLGen virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

dl.dropboxusercontent.com
ocsp.digicert.com

How to determine Backdoor.IRCBot.OLGen?


File Info:

crc32: E53DFB05
md5: eb21e07ae7573731cf39093c9d59a946
name: EB21E07AE7573731CF39093C9D59A946.mlw
sha1: 55c433a1058a0b433910bc73506d999aeba72556
sha256: 1460e964bfa84328c55b81a3df5144417ff742be4219f49911607dd67acb1163
sha512: 727260d0b6322d73f05f91fd54fc4c3e2f93a0a76dfc587032d028b26298038407be4060dedccf4051a20dc15bacdec774a3779e324a0cec848aeda90d281cff
ssdeep: 24576:OthEVaPqLD2LKmOOhBm5B807h1SE1Tk70TrcMchJLY:WEVUcD2LKm/hBkfWERkQTAMcD
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: tesss.ex.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: tesss.ex.exe

Backdoor.IRCBot.OLGen also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen.27583
CynetMalicious (score: 99)
ALYacGen:Variant.MSILKrypt.11
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.9857
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:MSIL/Blocker.89180c26
Cybereasonmalicious.ae7573
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.AST
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Psdownload-9799296-0
KasperskyTrojan-Ransom.Win32.Blocker.cclc
BitDefenderGen:Variant.MSILKrypt.11
NANO-AntivirusTrojan.Win32.Zapchast.dcmmdd
MicroWorld-eScanGen:Variant.MSILKrypt.11
TencentWin32.Trojan.Blocker.Aker
Ad-AwareGen:Variant.MSILKrypt.11
SophosMal/Generic-R
ComodoTrojWare.MSIL.TrojanDropper.Agent.~Ajv@1zen4r
F-SecureDropper.DR/AutoIt.Gen
BitDefenderThetaGen:NN.ZemsilF.34126.zn0@a4GsWUl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.eb21e07ae7573731
EmsisoftGen:Variant.MSILKrypt.11 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.eiw
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDropper:MSIL/Habbo.A
GDataGen:Variant.MSILKrypt.11
McAfeeArtemis!EB21E07AE757
MAXmalware (ai score=100)
VBA32Trojan-Downloader.Autoit.gen
MalwarebytesBackdoor.IRCBot.OLGen
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:djpYN1VdcxZIoKHuUZfdBA)
IkarusWorm.Win32.AutoIt
MaxSecureDropper.Agent.ajv
FortinetMSIL/Dropper.JV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.IRCBot.OLGen?

Backdoor.IRCBot.OLGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment