Backdoor

Backdoor.Win32.IRCNite.cbv removal instruction

Malware Removal

The Backdoor.Win32.IRCNite.cbv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.IRCNite.cbv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Win32.IRCNite.cbv?


File Info:

name: 1A2C04BE334F781A8836.mlw
path: /opt/CAPEv2/storage/binaries/5428debc7f315b71372ed5903c2c7b0e8c6cc296d004afd84dc764257c9ebc8b
crc32: 8B1B8551
md5: 1a2c04be334f781a883635b2ebc2f59e
sha1: 1775ebf42dbbbc4b88092ad8c1eb6239d8f4837e
sha256: 5428debc7f315b71372ed5903c2c7b0e8c6cc296d004afd84dc764257c9ebc8b
sha512: 2dce6a92345b47726e17bf178519bb1adc60dd2081042bf7ff9b4cd8f87b3adf5d2beb5a32e9dd26ad1936c42bf98965959f54746139ef2dca7eaed0d8199ba3
ssdeep: 3072:XT2xNfzEmPUac0yCRS9EK0TLmwAvU+7VZ/:DkPpe0msoVZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EC3E151B6E0CDFAE4B5813CB365CAD88FB4208A4B1B34958C50108EDC65E47AD5FFE2
sha3_384: a215e794b75ba0fb8f30171d1c0caa6eaf784e8dca3fa9428089cf26ead07e96c9ea04034fdcf30e9d84c6f436f02b7b
ep_bytes: 558bec83ec408165f40000000083ebc4
timestamp: 2009-07-11 01:18:33

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Shockwave Flash 8.0 r22
FileExtents: swf|spl|mfp
FileOpenName: Macromedia Flash movie (*.swf)|FutureSplash movie (*.spl)|Macromedia Flash Paper (*.mfp)
MIMEType: application/x-shockwave-flash|application/futuresplash
ProductName: Shockwave Flash
FileVersion: 8,0,22,0
InternalName: Macromedia Flash Player 8.0
LegalCopyright: Copyright © 1996-2005 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: npswf32.dll
ProductVersion: 8,0,22,0
Debugger: 0
Translation: 0x0409 0x04b0

Backdoor.Win32.IRCNite.cbv also known as:

BkavW32.Vetor.PE
LionicTrojan.Win32.Generic.lwsc
Elasticmalicious (high confidence)
DrWebWin32.Virut.56
CynetMalicious (score: 100)
FireEyeGeneric.mg.1a2c04be334f781a
CAT-QuickHealW32.Virut.G
McAfeeW32/Ramnit.y
CylanceUnsafe
ZillyaBackDoor.IRCNite.Win32.3
SangforBackdoor.Win32.IRCNite.cbv
K7AntiVirusTrojan ( 0041ada71 )
AlibabaVirus:Win32/Virut.9a3beb28
K7GWTrojan ( 0041ada71 )
Cybereasonmalicious.e334f7
ArcabitWin32.Virtob.Gen.12
BitDefenderThetaAI:FileInfector.C9457D4313
VirITWin32.Scribble.AC
CyrenW32/Ramnit.F.gen!Eldorado
SymantecPacked.Protexor!gen1
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallWORM_PALEVO.SMGD
Paloaltogeneric.ml
ClamAVWin.Trojan.Ramnit-6743044-0
KasperskyBackdoor.Win32.IRCNite.cbv
BitDefenderWin32.Virtob.Gen.12
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C
MicroWorld-eScanWin32.Virtob.Gen.12
AvastWin32:Vitro [Inf]
TencentBackdoor.Win32.Ircnite.cbv
Ad-AwareWin32.Virtob.Gen.12
SophosML/PE-A + Troj/Bckdr-RLO
ComodoVirus.Win32.Virut.CE@5jedjj
BaiduWin32.Virus.Virut.gen
VIPREVirus.Win32.Virut.ce.6 (v)
TrendMicroWORM_PALEVO.SMGD
McAfee-GW-EditionBehavesLike.Win32.Infected.ch
EmsisoftWin32.Virtob.Gen.12 (B)
IkarusTrojan.Crypt
JiangminWin32/Virut.bt
AviraW32/Virut.Gen
KingsoftWin32.Infected.Virut.sr.(kcloud)
GridinsoftRansom.Win32.Miner.sa
MicrosoftVirus:Win32/Virut.EPO
ZoneAlarmBackdoor.Win32.IRCNite.cbv
GDataWin32.Virtob.Gen.12
TACHYONVirus/W32.Virut.Gen
AhnLab-V3Win32/Virut.E
Acronissuspicious
VBA32Malware-Cryptor.Win32.General.4
MAXmalware (ai score=84)
APEXMalicious
RisingVirus.Virut!1.A08B (CLOUD)
YandexTrojan.GenAsa!I0KSJszmQnc
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.F
AVGWin32:Vitro [Inf]
PandaW32/Downloader.YFY.worm
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.IRCNite.cbv?

Backdoor.Win32.IRCNite.cbv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment