Malware

IRC/Randon.BT removal tips

Malware Removal

The IRC/Randon.BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IRC/Randon.BT virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Attempted to write to a harddisk volume
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine IRC/Randon.BT?


File Info:

name: 4393436CF2B387B5ED52.mlw
path: /opt/CAPEv2/storage/binaries/b538af5e502e6fdb60c6239dd3245c71621b31916c8567d53d8994f4ec81f261
crc32: 51C1C8EA
md5: 4393436cf2b387b5ed52983b90fab7a6
sha1: dd286f82529dab529bcbfb188be72924f77367e5
sha256: b538af5e502e6fdb60c6239dd3245c71621b31916c8567d53d8994f4ec81f261
sha512: 815661268897bd3df07f999b0a10dc9fb36dc853aa469f178ec8996eec311ed085370ae97efd89e35f5f442ead2df94f19d91f8fc11934e86eeefd71b8ef340b
ssdeep: 24576:38fpIjZNh88AvnMrwdqgMQunypSi3ysJ90aEEAXlt42Cm+e0+vuQY8M:38KjTynMrzQuwysbRkKRZ+WQzM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F552314F783C0F6F05147701EEE333AE439FB6596B4B108AB910B1E1CB1692AE5867B
sha3_384: a54f3503a596797c2b1677df132c58b36d8c29ef817c2e767ac04fe935ad606dd189fbec90226bd6563d10176e51720f
ep_bytes: e8f32a000050e83b3301000000000090
timestamp: 2007-09-20 12:34:46

Version Info:

0: [No Data]

IRC/Randon.BT also known as:

LionicRiskware.Win32.mIRC.1!c
McAfeeArtemis!4393436CF2B3
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Irc.Vj7x
AlibabaWorm:Win32/Randon.eadeea4e
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITBackdoor.Win32.CU
ESET-NOD32IRC/Randon.BT
APEXMalicious
Kasperskynot-a-virus:Client-IRC.Win32.mIRC.621
NANO-AntivirusTrojan.Win32.GenericL.dhbnld
AvastWin32:Trojan-gen
TencentWin32.Trojan.Mirc.Dplw
F-SecureBackdoor.BDS/IRC.Critical.3
DrWebBackDoor.IRC.72
ZillyaAdware.AddLyrics.Win64.565
TrendMicroBKDR_MOO.DLL
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
Ikarusnot-a-virus:Client-IRC.Win32.mIRC
WebrootW32.Gen.BT
GoogleDetected
AviraBDS/IRC.Critical.3
Antiy-AVLTrojan/Win32.SGeneric
XcitiumMalware@#2tsl3aox63xtn
ZoneAlarmnot-a-virus:Client-IRC.Win32.mIRC.621
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32Backdoor.IRC
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_MOO.DLL
RisingTrojan.Bitrep!8.F596 (CLOUD)
YandexRiskware.IRC!YyOK4yNqAdM
FortinetPossibleThreat
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove IRC/Randon.BT?

IRC/Randon.BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment