Home Malware Programs Backdoors Backdoor.IRCbot.gen!Y

Backdoor.IRCbot.gen!Y

Posted: September 10, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 23
First Seen: September 10, 2012
Last Seen: June 12, 2019
OS(es) Affected: Windows

Backdoor.IRCbot.gen!Y is a backdoor Trojan that is used by attackers primarily to make a profit on a corrupted PC visiting websites based on the algorithm of IRC bot, which is a part of the malware threat. Backdoor.IRCbot.gen!Y establishes an unauthorized channel, through which attackers can control the IRC bot. An IRC bot is a client, such as Internet Explorer or Mozilla that is, program created to connect to the Internet that connects to servers specified by attackers and browse through them according to the commands. This may cause distribution of other malware threats into the vulnerable machine. Backdoor.IRCbot.gen!Y (Backdoor:Win32/IRCbot.gen!Y) allows attackers to release new commands to the IRC bot so that it may load malicious content to your computer or open annoying websites.

Aliases

Suspicious file [Panda]unknown virus Win32/DH{A2EJICQiDw} [AVG]Backdoor.Win32.IRCBot [Ikarus]Backdoor:Win32/IRCbot.gen!Y [Microsoft]TR/Downloader.Gen [AntiVir]Win32.HLLW.Autoruner.origin [DrWeb]UnclassifiedMalware [Comodo]Mal/IRCBot-B [Sophos]Dropped:Generic.Malware.SYdld.49BFDCD4 [BitDefender]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:Malware-gen [Avast]W32.IRCBot [Symantec]W32/Rewal.gen1 [F-Prot]Virus [K7AntiVirus]W32/Sdbot.worm!os [McAfee]
More aliases (22)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\winlogon.exe File name: winlogon.exe
Size: 33.28 KB (33280 bytes)
MD5: 34e839bab9099ed0e9d24cdeb1cf6901
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: September 10, 2012
Loading...