Categories: Backdoor

Backdoor:Win32/IRCbot.FU removal instruction

The Backdoor:Win32/IRCbot.FU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/IRCbot.FU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Backdoor:Win32/IRCbot.FU?


File Info:

name: 0082790D80BB214433BC.mlwpath: /opt/CAPEv2/storage/binaries/9351541681da809e9eb0629aa2c80fde10ad6c49d3a976fca519ffdc3700b828crc32: 9EB96CCFmd5: 0082790d80bb214433bc6bce48f5f730sha1: 65bf35f3b839a628572012d811c59a5ca6b6e7bbsha256: 9351541681da809e9eb0629aa2c80fde10ad6c49d3a976fca519ffdc3700b828sha512: 16c078071a81164d59472ba52f0edaebfabc3dd002cab0dbe35fed3c53683ab5a6f7469a315f1c754493ffaf1653472541b0faf85b670d2959ce6ba3c8d426cassdeep: 12288:+NUc4Qr3JfzyPy3neH2Zpky4I7XJfDd/vVxGy3Klfnq:gUcHr3R2l2Z557XPvvG10type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T12EC423F236DA48B2DCA6CB711732AFACD539A81393021787BF00CD5B77B34C65609166sha3_384: 3139e2edfaadc0336f846bb32d067fb9348bf351f47c2f8734f9e0dd4a592bbae84841d7a74cc8cdd54bd84c2f8cd5b5ep_bytes: 558bec81ec80010000535633db57895dtimestamp: 2007-03-31 15:09:55

Version Info:

0: [No Data]

Backdoor:Win32/IRCbot.FU also known as:

Lionic Worm.Win32.Generic.o!c
MicroWorld-eScan Gen:Variant.Zusy.419885
FireEye Generic.mg.0082790d80bb2144
CAT-QuickHeal Trojan.Skeeyah.26682
ALYac Gen:Variant.Zusy.419885
Malwarebytes Malware.AI.652635944
VIPRE Gen:Variant.Zusy.419885
K7AntiVirus Trojan ( 7000000f1 )
BitDefender Gen:Variant.Zusy.419885
Cybereason malicious.d80bb2
Arcabit Trojan.Zusy.D6682D
BitDefenderTheta AI:Packer.A0CFE98D1E
Cyren W32/Delfloader.B.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Dewnad.AP
TrendMicro-HouseCall Mal_Banld-1
Paloalto generic.ml
ClamAV Win.Virus.Ramnit-6998058-0
Kaspersky UDS:Worm.Win32.Generic
Alibaba Worm:Win32/Dewnad.e9a5d3db
NANO-Antivirus Trojan.Win32.Crypted.detnb
Cynet Malicious (score: 100)
Rising Trojan.Generic@AI.97 (RDML:Wo5/ZWqnhZSW4R+Tn2DEKQ)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Delphi.Gen
DrWeb Trojan.DownLoader5.3549
TrendMicro Mal_Banld-1
McAfee-GW-Edition GenericR-JHL!16A69ED3DA5B
SentinelOne Static AI – Suspicious PE
Trapmine malicious.moderate.ml.score
Emsisoft Gen:Variant.Zusy.419885 (B)
APEX Malicious
Avira TR/Dldr.Delphi.Gen
MAX malware (ai score=84)
Antiy-AVL Worm/Win32.Bybz
Kingsoft Win32.Heur.KVMH017.a.(kcloud)
Microsoft Backdoor:Win32/IRCbot.FU
ZoneAlarm UDS:Worm.Win32.Generic
GData Gen:Variant.Zusy.419885
Google Detected
AhnLab-V3 Worm/Win32.Bybz.R195404
Acronis suspicious
McAfee Artemis!0082790D80BB
VBA32 Worm.Bybz
Cylance Unsafe
Yandex Worm.Dewnad!zeu+a4VRsrw
Ikarus Worm.Win32.Bybz
Fortinet W32/Delf.SOU!tr
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (W)

How to remove Backdoor:Win32/IRCbot.FU?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Should I remove “Trojan.Win32.Ekstak.axjoy”?

The Trojan.Win32.Ekstak.axjoy is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

Application.Downloader.AWT removal

The Application.Downloader.AWT is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

What is “Malware.AI.4129591088”?

The Malware.AI.4129591088 is considered dangerous by lots of security experts. When this infection is active,…

36 mins ago

Lazy.508865 (file analysis)

The Lazy.508865 is considered dangerous by lots of security experts. When this infection is active,…

41 mins ago

Mikey.166133 removal tips

The Mikey.166133 is considered dangerous by lots of security experts. When this infection is active,…

45 mins ago

Jaik.11356 information

The Jaik.11356 is considered dangerous by lots of security experts. When this infection is active,…

56 mins ago