Backdoor

About “Backdoor:Win32/IRCbot!Y” infection

Malware Removal

The Backdoor:Win32/IRCbot!Y is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/IRCbot!Y virus can do?

  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
vbotv5.serveirc.com

How to determine Backdoor:Win32/IRCbot!Y?


File Info:

crc32: C165294D
md5: 731c1bf8d17a111e525eb6d12ef29166
name: 731C1BF8D17A111E525EB6D12EF29166.mlw
sha1: d5f3b1627897ce9385fdd4ce823abc24926b56b2
sha256: a0030e17b7b09e378cb254a691f90fb95a761965d89fcdc056df76740c3543ec
sha512: 2b845ee38c44bd8f7d3046fcc407c66ee9efc5e725c74d1451146fb9f7cf64a8fae051213ea5559c6962abaae55fe829828130f5a651a7c14d7c4ec70f833a58
ssdeep: 384:5k7qPxNcrqcMoozl3mcAiFxAHi7UhUChGB9B1X0bmUkeKv9:5k7qPxEMoozl28VJChMETkJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/IRCbot!Y also known as:

BkavW32.AIDetect.malware2
K7AntiVirusBackdoor ( 00001e5b1 )
DrWebDLOADER.IRC.Trojan
CynetMalicious (score: 100)
ALYacGeneric.Malware.SB!dld!.9ED88908
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.43511
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Blocker.194cb812
K7GWBackdoor ( 00001e5b1 )
Cybereasonmalicious.8d17a1
BaiduWin32.Trojan.IRCBot.c
CyrenW32/Bloop.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.Agent.AKL
APEXMalicious
AvastWin32:Flooder-GT [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.jczk
BitDefenderGeneric.Malware.SB!dld!.9ED88908
NANO-AntivirusTrojan.Win32.Rbot.twqju
MicroWorld-eScanGeneric.Malware.SB!dld!.9ED88908
TencentWin32.Worm.Autorun.Aeee
Ad-AwareGeneric.Malware.SB!dld!.9ED88908
SophosML/PE-A
ComodoMalware@#2iskrqnfttto3
BitDefenderThetaAI:Packer.2F85F75B1F
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.Dropper.lm
FireEyeGeneric.mg.731c1bf8d17a111e
EmsisoftGeneric.Malware.SB!dld!.9ED88908 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/Agent
AviraWORM/Rbot.Gen
eGambitGeneric.Worm
Antiy-AVLTrojan/Generic.ASMalwS.ED3130
KingsoftWin32.Heur.KVMH012.a.(kcloud)
MicrosoftBackdoor:Win32/IRCbot.gen!Y
ZoneAlarmTrojan-Ransom.Win32.Blocker.jczk
GDataGeneric.Malware.SB!dld!.9ED88908
AhnLab-V3Worm/Win32.AutoRun.R8161
Acronissuspicious
McAfeeW32/IRCBot.gen.f
MAXmalware (ai score=100)
MalwarebytesBackdoor.IRCBot
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_DLDER
RisingTrojan.Generic@ML.97 (RDML:lvJnyabserg8s739d3bNLw)
YandexTrojan.GenAsa!FGq142Li/Jw
IkarusTrojan.Win32.Malagent
FortinetW32/IRCBot.C!worm
AVGWin32:Flooder-GT [Trj]

How to remove Backdoor:Win32/IRCbot!Y?

Backdoor:Win32/IRCbot!Y removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment