Malware

About “Win32/IRCBot.NEU” infection

Malware Removal

The Win32/IRCBot.NEU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/IRCBot.NEU virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/IRCBot.NEU?


File Info:

name: 93B9E2A68DA657D3239A.mlw
path: /opt/CAPEv2/storage/binaries/af72b39e4ba98b3c426aea64bc9fc77f20ce0628fe031e54a2ddeaf5d990fecb
crc32: 2527A005
md5: 93b9e2a68da657d3239a492a774d913d
sha1: 981e31a2cb5a12e94e714b7f85ad60212a7512c7
sha256: af72b39e4ba98b3c426aea64bc9fc77f20ce0628fe031e54a2ddeaf5d990fecb
sha512: a1d0e419e68c5f07a642686f8a7760490b97561ae7382db0e2efd02895dcdb436af5fd631c3f68338abf2254369433c3c2553af1381dd47f3d90a88c0c139b22
ssdeep: 3072:lJfuq8IzyLHIDkuwRDl/2mmatecv2suHx5lRyvCHRcsvHBdGGE+0LgP1g+YJbxKu:nuq1yykW2asCxLTxfGat/YJz8Shh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A440216B151C1B1D02099BC0D2BD1DCA73BFA303D3A1583BBA56FED5DFD18A6A0C896
sha3_384: 8c9d278e2d0730110c1b9df70ab7f2b6ed7faae3e24728a7d9255a952cbceefc87ca12732e92560f912aff0706797be2
ep_bytes: 558becb9060000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/IRCBot.NEU also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.62699263
ClamAVWin.Malware.Delf-6717516-0
FireEyeGeneric.mg.93b9e2a68da657d3
CAT-QuickHealTrojan.GenericPMF.S30131323
ALYacTrojan.GenericKD.62699263
Cylanceunsafe
ZillyaBackdoor.Delf.Win32.22735
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.68da65
BaiduWin32.Trojan.Delf.j
CyrenW32/Trojan.BTCF-4015
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32Win32/IRCBot.NEU
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Delf.ars
BitDefenderTrojan.GenericKD.62699263
NANO-AntivirusTrojan.Win32.Delf.dbtjno
SUPERAntiSpywareTrojan.Agent/Gen-Delf
AvastWin32:BotX-gen [Trj]
TencentTrojan.Win32.IRCbot.nrc
TACHYONBackdoor/W32.DP-Delf.Zen
EmsisoftTrojan.GenericKD.62699263 (B)
F-SecureWorm.WORM/Rbot.Gen
DrWebBackDoor.IRC.Sdbot.16412
VIPRETrojan.GenericKD.62699263
TrendMicroBKDR_MYDOOM.SMM
McAfee-GW-EditionBehavesLike.Win32.ExploitMydoom.dc
Trapminemalicious.high.ml.score
SophosTroj/Luiha-BN
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.MyDoom.B
JiangminBackdoor/Delf.hxo
AviraWORM/Rbot.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Delf
GridinsoftBackdoor.Win32.Delf.bot!s1
XcitiumBackdoor.Win32.Agent.~AACE@2m6u4
ArcabitTrojan.Generic.D3BCB6FF
ViRobotBackdoor.Win32.A.Delf.48641
ZoneAlarmBackdoor.Win32.Delf.ars
MicrosoftTrojan:Win32/CoinMiner!pz
GoogleDetected
AhnLab-V3Backdoor/Win.Delf.R497059
Acronissuspicious
McAfeeExploit-Mydoom
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Delf
MalwarebytesGeneric.Backdoor.IRCBot.DDS
PandaBck/Delf.AAQ
TrendMicro-HouseCallBKDR_MYDOOM.SMM
RisingBackdoor.Delf!1.64C1 (CLASSIC)
YandexTrojan.GenAsa!kSqZtZW01VM
IkarusTrojan.Win32.IRCBot
MaxSecureTrojan.W32.Delf.Ars
FortinetW32/Delf.NRF!tr
BitDefenderThetaAI:Packer.A5E777971D
AVGWin32:BotX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/IRCBot.NEU?

Win32/IRCBot.NEU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment