Trojan

Trojan:Win32/IRCbot.RH!MTB (file analysis)

Malware Removal

The Trojan:Win32/IRCbot.RH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IRCbot.RH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

How to determine Trojan:Win32/IRCbot.RH!MTB?


File Info:

crc32: 03718EEA
md5: 1ceeab095c0371969974d28d310a6c7c
name: 1CEEAB095C0371969974D28D310A6C7C.mlw
sha1: fce76add17483f3c965e167aea483bb2df8f4a33
sha256: 797c21e0fde8d090e8db3e26540a7de02177b16e0fcc273f9e28b1bca3bdd6ad
sha512: a4df7715ebcdf90855dc8a8d4c71c3f45191f210308043259872b8c6731cac0054c67390213a49fcbf205aceb68b26ea4f314bc88b6aafd1aeb59b7eba69e1b0
ssdeep: 12288:z+CPcYaUs91BNBOwx/HxdS9M8PkpHRELwdQ/PE+aEhIAFUc8QxYIIwSYci6qR41:NcYtsDD5RE36Ab8yYIIwZclD1
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/IRCbot.RH!MTB also known as:

K7AntiVirusTrojan ( 0057ffc71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.364
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.978999
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.d17483
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
ClamAVWin.Trojan.Ulpm-9835226-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Graftor.978999
MicroWorld-eScanGen:Variant.Graftor.978999
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Graftor.978999
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34266.XmW@au6AeWn
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGen:Variant.Graftor.978999
EmsisoftGen:Variant.Graftor.978999 (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitCoinMiner.wcz
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68A
MicrosoftTrojan:Win32/IRCbot.RH!MTB
ArcabitTrojan.Graftor.DEF037
GDataGen:Variant.Graftor.978999
AhnLab-V3Malware/Gen.RL_Reputation.R366811
McAfeeGenericRXOC-ZZ!1CEEAB095C03
MAXmalware (ai score=83)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.GenAsa!XCD5a2BYWlc
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.74654884.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]

How to remove Trojan:Win32/IRCbot.RH!MTB?

Trojan:Win32/IRCbot.RH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment