Backdoor

About “Backdoor.Ircbotn” infection

Malware Removal

The Backdoor.Ircbotn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Ircbotn virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Backdoor.Ircbotn?


File Info:

name: 0717324BC858C565B01A.mlw
path: /opt/CAPEv2/storage/binaries/622bee33ccbd897bc4defd751db6fc313a27d1874c29a689898d51937963f311
crc32: CE1D9BE6
md5: 0717324bc858c565b01af5a11a757915
sha1: aa3e8634d1700a120201022256abbb49f19ec088
sha256: 622bee33ccbd897bc4defd751db6fc313a27d1874c29a689898d51937963f311
sha512: 7c4c3cd9f20bed5506475617386c5a05153a419d52bd22d1d8e1cd38a010928e7bc579e5f6d981de7740f7a0b0cbc0312350bf34154640011f18718e923b5b74
ssdeep: 3072:Cm4MwWYm3434iFrmsA7uCEeiUhNK3v+2rR3mpm/UX:isd7uCEeiUhNK3v+2rR3K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107C3F831F753A022CD72153CA75993FD8DEDDA332604846B97CCCA262DB4BA5DF22606
sha3_384: f11fcb86c25f9d205005aa331d63c417a22d14adbe5e914668493c974801e70ae39eac385dc1b83143c261bd757249ad
ep_bytes: ffff0000ff75e8e8b41800006a108d45
timestamp: 2006-12-11 14:26:14

Version Info:

0: [No Data]

Backdoor.Ircbotn also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGeneric.Dacic.4254EF66.A.528B662D
ClamAVWin.Malware.Sfwx-9853337-0
FireEyeGeneric.mg.0717324bc858c565
CAT-QuickHealBackdoor.Ircbotn
McAfeeExploit-DcomRpc.c.gen
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CyrenW32/Agent.FZA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGeneric.Dacic.4254EF66.A.528B662D
AvastWin32:Allaple-D [Trj]
EmsisoftGeneric.Dacic.4254EF66.A.528B662D (B)
BaiduWin32.Worm.Rbot.a
VIPREGeneric.Dacic.4254EF66.A.528B662D
TrendMicroTROJ_GEN.R03BC0DIE23
McAfee-GW-EditionBehavesLike.Win32.ExploitDcomRpc.cm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGeneric.Dacic.4254EF66.A.528B662D
MAXmalware (ai score=81)
Antiy-AVLHackTool/Win32.Agent.a
ArcabitGeneric.Dacic.4254EF66.A.528B662D
MicrosoftBackdoor:Win32/IRCbot.gen!N
GoogleDetected
AhnLab-V3Worm/Win32.Allaple.R25156
ALYacGeneric.Dacic.4254EF66.A.528B662D
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DIE23
RisingTrojan.Generic@AI.100 (RDML:QlCaVBICBLiEL6m5hRyFzQ)
IkarusBackdoor.Win32.Allaple
MaxSecureTrojan.Malware.321012.susgen
FortinetW32/Generic.AC.1A4F05!tr
AVGWin32:Allaple-D [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Ircbotn?

Backdoor.Ircbotn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment