Backdoor

Generic.Backdoor.IRCBot.DDS removal instruction

Malware Removal

The Generic.Backdoor.IRCBot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Backdoor.IRCBot.DDS virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Generic.Backdoor.IRCBot.DDS?


File Info:

name: D71728A04A86BBC9B093.mlw
path: /opt/CAPEv2/storage/binaries/30dfc2b070672ed5b6fc37831fc4177bf0fc0c4560bcca733ebc62f021f554b1
crc32: DCA8084E
md5: d71728a04a86bbc9b093c974dd31720c
sha1: 669a0f3b8c92f628d6ac95c7b763170e501f60e3
sha256: 30dfc2b070672ed5b6fc37831fc4177bf0fc0c4560bcca733ebc62f021f554b1
sha512: e0cbb6ba614264a35bcf599212ae0b3011c1c7e8c93a3cf79d4f28b89f3608bed05bef57b1f1e9786c5858720b7d3d188bfa682ba26a79c845422d98d70053a4
ssdeep: 768:FmiOQauOECLIK8u4qc+5aIjK4LrP+K5fE6ry7298P2dUV0:Fmip8JB5aOLL+K5E6L8A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE736B53E880D833D0618EFE8D6BE4A9F65F36102F253127779A5FCD993DA820A1C592
sha3_384: b50096ddb7ccb6f7711a51ec497a23447d4053647375d9f79b84e2cbf5a9f930693b74ddb02b9d4054e0652225c67c5e
ep_bytes: 8d45f4ba04000000e873abffff6a008b
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Generic.Backdoor.IRCBot.DDS also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Fugrafa.278453
ClamAVWin.Trojan.Gobot-20
ALYacGen:Variant.Fugrafa.278453
MalwarebytesGeneric.Backdoor.IRCBot.DDS
VIPREGen:Variant.Fugrafa.278453
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Delf_Troj.EL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fugrafa.278453
AvastWin32:Delf-HW [Trj]
TACHYONTrojan/W32.Agent.73728.GOC
EmsisoftGen:Variant.Fugrafa.278453 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d71728a04a86bbc9
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.QISNP9
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Fugrafa.D43FB5
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!D71728A04A86
MAXmalware (ai score=82)
VBA32suspected of Backdoor.Delf.31
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH09D523
RisingBackdoor.IRCbot!1.C104 (CLASSIC)
IkarusP2P-Worm.Win32.Delf
MaxSecureTrojan.Malware.204209788.susgen
FortinetW32/Agent.GBOT!tr
BitDefenderThetaGen:NN.ZelphiF.36132.eGY@aq111Ep
AVGWin32:Delf-HW [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Backdoor.IRCBot.DDS?

Generic.Backdoor.IRCBot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment