Malware

Icirac.4 removal guide

Malware Removal

The Icirac.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Icirac.4 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify UAC prompt behavior
  • Uses suspicious command line tools or Windows utilities

How to determine Icirac.4?


File Info:

crc32: 61B4C8A0
md5: 9bd5f02c83314deea4b7f9fa6c33ac7f
name: 9527.exe
sha1: decbfa0a463597461cfdf7f6754d6b6ff163c325
sha256: d737bc3a8910128f1e2ef61de97e9d7bf49d1d2e54963a26b9c259989ea1529f
sha512: bd5cd97d52f06a2499a66f6293cb0723e0c3b37079380247b8e2afa92e41240487beb3e7d4c3380d735e195202dc8083d9f38c6f902a98bd6597a8e465e62a64
ssdeep: 1536:i625Dpcpnwwb6Xmg/lS/9UbzR4jDUsTla3nouy8:i64DCzUdMUbzR4n3TlaXout
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Icirac.4 also known as:

MicroWorld-eScanGen:Variant.Icirac.4
FireEyeGeneric.mg.9bd5f02c83314dee
CAT-QuickHealTrojan.Bulta.A5
ALYacGen:Variant.Icirac.4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055d0f01 )
BitDefenderGen:Variant.Icirac.4
K7GWTrojan ( 0055d0f01 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroBKDR_SDBOT.SM
BaiduWin32.Trojan.Agent.asz
F-ProtW32/Bulta.B.gen!Eldorado
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Dropper.Gh0stRAT-6992450-0
GDataGen:Variant.Icirac.4
KasperskyBackdoor.Win32.Sdbot.agiy
AlibabaBackdoor:Win32/Sdbot.3e5d2164
NANO-AntivirusTrojan.Win32.MLW.duuovm
AegisLabTrojan.Win32.Sdbot.m!c
RisingTrojan.DDOS!1.AAC6 (CLOUD)
Ad-AwareGen:Variant.Icirac.4
EmsisoftGen:Variant.Icirac.4 (B)
ComodoBackdoor.Win32.Sdbot.AM@83hwfp
F-SecureAdware.ADWARE/Taranis.993
DrWebDDoS.5784
ZillyaBackdoor.SdBot.Win32.1
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.HLLP.pc
MaxSecureTrojan.Malware.8393240.susgen
Trapminemalicious.moderate.ml.score
SophosMal/Behav-044
IkarusTrojan.Win32.DDos
CyrenW32/Bulta.B.gen!Eldorado
JiangminBackdoor.SdBot.hk
AviraADWARE/Taranis.993
Antiy-AVLTrojan[Backdoor]/Win32.Sdbot.aerk
Endgamemalicious (moderate confidence)
ArcabitTrojan.Icirac.4
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmBackdoor.Win32.Sdbot.agiy
MicrosoftTrojan:Win32/Bulta!rfn
TACHYONBackdoor/W32.SdBot.109056.H
AhnLab-V3Trojan/Win32.Dorv.R304564
Acronissuspicious
McAfeeGenericRXAA-AA!9BD5F02C8331
MAXmalware (ai score=85)
VBA32BScope.Trojan.Win32.Inject.2
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/DDoS.Agent.NBI
TrendMicro-HouseCallBKDR_SDBOT.SM
TencentMalware.Win32.Gencirc.10b8acdf
YandexWorm.Sdbot!np+qdcCwb3I
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.NBI!tr
BitDefenderThetaGen:NN.ZexaF.34100.dmGfai2ngdki
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.c83314
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.SdBot.A

How to remove Icirac.4?

Icirac.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment