Threat Database Trojans Trojan.IRCBot

Trojan.IRCBot

Threat Scorecard

Ranking: 10,172
Threat Level: 80 % (High)
Infected Computers: 4,297
First Seen: July 24, 2009
Last Seen: September 15, 2023
OS(es) Affected: Windows

Trojan.IRCBot is a backdoor Trojan program that is able to secretly enter a victim's PC without his/her knowledge. Once inside a system, Trojan.IRCBot will connect with an IRC server and receive commands from a remote attacker. Trojan.IRCBot is able to propagate via network shares, spam e-mails or infected downloads. Besides infected a PC with additional malware, Trojan.IRCBot will also put a victim's confidential information at risk of being stolen and used for criminal activities.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Sunbelt Trojan.Win32.Generic!BT
NOD32 MSIL/IRCBot.J
a-squared Trojan.MSIL.IRCBot.J!A2
Sunbelt Trojan.Win32.Generic.pak!cobra
NOD32 a variant of Win32/Injector.BKW
Ikarus Trojan.Win32.Ircbrute
BitDefender Trojan.Generic.KD.9975
a-squared Trojan.Win32.Ircbrute!IK
Sophos Mal/IRCBot-C
Prevx1 Heuristic: Suspicious File With Outbound Communica
Panda Suspicious file
Microsoft Trojan:Win32/SystemHijack.gen
Ikarus Win32.SuspectCrc
F-Secure W32/Horst.gen33
eSafe suspicious Trojan/Worm

SpyHunter Detects & Remove Trojan.IRCBot

File System Details

Trojan.IRCBot may create the following file(s):
# File Name MD5 Detections
1. dllcache.exe 0fc2d0e6af71e2f6a969d81314f9996c 287
2. dllcache.exe 5618a131c4f6224ab7a3420ed8c74d68 101
3. dllcache.exe 4c8f558ade7dd6320bda96ac54aba459 47
4. dllcache.exe 6079787505cdbdfcf3206e4b2a4aeac0 10
5. dllcache.exe deace83c93223143c78f1174161ef6ad 5
6. winsvc.exe 2b49585f2811734ccd2811f1a7004c06 3
7. file.exe 42e833dd8fb25b8ac7b0b19f4962ae6f 0

Registry Details

Trojan.IRCBot may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\dwmn.exe
%APPDATA%\local.exe
%APPDATA%\Microsoft\Windows\MMC\Explorer.exe
%APPDATA%\Window Updates\winupdt3.exe
%APPDATA%\winmgr.txt
%WINDIR%\jodrive32.exe
%WINDIR%\M-50502462522540258485045\winmgr.exe

Directories

Trojan.IRCBot may create the following directory or directories:

%ALLUSERSPROFILE%\Windows Update Service0
%USERPROFILE%\P-7-78-8964-9648-3874

Related Posts

Trending

Most Viewed

Loading...