Malware

Should I remove “Python/IRCBot.M”?

Malware Removal

The Python/IRCBot.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/IRCBot.M virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Looks up the external IP address

Related domains:

ipinfo.io
freegeoip.net
spdevb0t.dynu.com

How to determine Python/IRCBot.M?


File Info:

crc32: 32DFBE0F
md5: cd6a6bdc7739c8cb5dbed68fdc1413e0
name: CD6A6BDC7739C8CB5DBED68FDC1413E0.mlw
sha1: 2068c197f8ed0b0d921e98a63ff6219c0eade331
sha256: af992a2aa6b91c228959a4f0b3da5ab1c45293e363afdc150df38747462bd2c1
sha512: 9f1cb0d3d84e4a93be0b48dbe880cecde8e0a44e63849ab50bd8917e735766232de080588d5d2d3c7407f4a3ca2371ecffb78f1dd69effcb98d9b636bc22662c
ssdeep: 98304:VXmjdBAEoDCqpBLgXYRY8TSo5QAXZx7SnUqxeU4YhsYdEVP1QJtG:5mXxCzfPRYUSSQ+xox7hsVVP1QvG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010 Valve Corporation
InternalName: steamcmd (buildbot_steam-relclient-win32-builder_steam_rel_client_win32@steam-relclient-win32-builder)
FileVersion: 04.28.51.07
CompanyName: Valve Corporation
Source Control ID: 4285107
ProductName: Steam Client Bootstrapper
ProductVersion: 01.00.00.01
FileDescription: Steam Client Bootstrapper
OriginalFilename: steam.exe
Translation: 0x0409 0x04b0

Python/IRCBot.M also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Snojan.4!c
ALYacTrojan.GenericKD.6351832
CylanceUnsafe
SangforTrojan.Win32.Snojan.ccar
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Snojan.6f5f3a4e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c7739c
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/IRCBot.M
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Snojan.ccar
BitDefenderTrojan.GenericKD.6351832
NANO-AntivirusTrojan.Win32.Snojan.exsxpd
MicroWorld-eScanTrojan.GenericKD.6351832
TencentWin32.Trojan.Snojan.Taow
Ad-AwareTrojan.GenericKD.6351832
SophosMal/Generic-S
ComodoMalware@#28amxgn1bnmju
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WGB21
McAfee-GW-EditionBehavesLike.Win32.PUPXBC.tc
FireEyeGeneric.mg.cd6a6bdc7739c8cb
EmsisoftTrojan.GenericKD.6351832 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Snojan.dvyfq
eGambitUnsafe.AI_Score_89%
Antiy-AVLTrojan/Generic.ASMalwS.2175B86
MicrosoftTrojan:Win32/Occamy.CAF
GDataTrojan.GenericKD.6351832
McAfeeArtemis!CD6A6BDC7739
MAXmalware (ai score=94)
VBA32Trojan.Snojan
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WGB21
IkarusTrojan.Win32.Snojan
FortinetGenerik.PATCGU!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Python/IRCBot.M?

Python/IRCBot.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment