Backdoor

Backdoor.Win32.IRCBot.jt removal tips

Malware Removal

The Backdoor.Win32.IRCBot.jt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.IRCBot.jt virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Backdoor.Win32.IRCBot.jt?


File Info:

name: 77D8B3A20F753601C87B.mlw
path: /opt/CAPEv2/storage/binaries/ec877879b318bd76802989a1499aa2d2c958a804a64f48c5394f835dc8829d08
crc32: B052EEFA
md5: 77d8b3a20f753601c87bbcc87ebc26c0
sha1: 29157be71db7b583c0f23108480128c15192ae1f
sha256: ec877879b318bd76802989a1499aa2d2c958a804a64f48c5394f835dc8829d08
sha512: 4475aa5b38fbbe1ce226274ae736e66f55c01e6f34b84c7ab7170c974801d2cebcb983f84448f04753b1a81f5facc6cfb526b8d2c9120a2b5b479a1be0f87b81
ssdeep: 1536:d+r6rP6Bsh+FqaCr04N8w3tD/dSqzpWDUk76By:i6eY+7u3Sw3DhTku0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B937D2A1649CCE2D7A133B4865692324435E975C23B6343ABDBC7FB0FA0472661F6F1
sha3_384: 0e1e83e2f7e199bb3cc553b37eca863661248eaf1bcf707bc5c104918f251212c5339cb453bd882d22919c8703e6ff62
ep_bytes: e9550000005a565750515389d3e84801
timestamp: 2106-02-07 06:28:15

Version Info:

0: [No Data]

Backdoor.Win32.IRCBot.jt also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.SI!dld!g.46B97B29
CAT-QuickHealWorm.Gaobot.Gen
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00553f0b1 )
K7GWTrojan ( 00553f0b1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.B86B65611E
VirITI-WORM.Mytob.BX
CyrenW32/Ircbot.BCYP-6385
SymantecW32.Gaobot.gen!poly
tehtrisGeneric.Malware
ESET-NOD32Win32/Mytob.QA
TrendMicro-HouseCallMal_Bot
AvastWin32:HBPECrypt-A [Wrm]
ClamAVWin.Worm.Mytob-203
KasperskyBackdoor.Win32.IRCBot.jt
BitDefenderGeneric.Malware.SI!dld!g.46B97B29
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
TencentBackdoor.Win32.Agobot.za
SophosW32/Mytob-Fam
F-SecureTrojan.TR/Downloader.Gen
DrWebWin32.HLLW.Agobot
VIPREGeneric.Malware.SI!dld!g.46B97B29
TrendMicroMal_Bot
McAfee-GW-EditionBehavesLike.Win32.Ardurk.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.77d8b3a20f753601
EmsisoftGeneric.Malware.SI!dld!g.46B97B29 (B)
GDataWin32.Trojan.PSE.1BGLT85
GoogleDetected
AviraTR/Downloader.Gen
Antiy-AVLWorm/Win32.AgoBot.a
XcitiumBackdoor.Win32.Agobot.hn0@1d9dgj
ArcabitGeneric.Malware.SI!dld!g.46B97B29
ViRobotWorm.Win32.Agobot.gen
ZoneAlarmBackdoor.Win32.IRCBot.jt
MicrosoftWorm:Win32/Gaobot
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.R7768
Acronissuspicious
VBA32Backdoor.IRCBot
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaMalicious Packer
APEXMalicious
RisingWorm.Mytob.hf (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AgoBot.fam!worm
AVGWin32:HBPECrypt-A [Wrm]
Cybereasonmalicious.71db7b
DeepInstinctMALICIOUS

How to remove Backdoor.Win32.IRCBot.jt?

Backdoor.Win32.IRCBot.jt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment