Home Malware Programs Trojans Trojan.IRCBot

Trojan.IRCBot

Posted: February 22, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 10,169
First Seen: July 24, 2009
Last Seen: October 17, 2024
OS(es) Affected: Windows

Trojan.IRCBot is a malicious banking Trojan that runs in the background and displays characteristics of a ZBot. Trojan.IRCBot can disable the firewall and will attempt to steal sensitive financial data (credit card numbers, online banking login details). Trojan.IRCBot creates startup registry entries that loads when Windows boots up. Trojan.IRCBot may represent a severe security risk to the compromised system or its network environment and should be removed immediately.

Aliases

Trojan.Win32.Generic!BT [Sunbelt]MSIL/IRCBot.J [NOD32]Trojan.MSIL.IRCBot.J!A2 [a-squared]Trojan.Win32.Generic.pak!cobra [Sunbelt]a variant of Win32/Injector.BKW [NOD32]Trojan.Win32.Ircbrute [Ikarus]Trojan.Generic.KD.9975 [BitDefender]Trojan.Win32.Ircbrute!IK [a-squared]Mal/IRCBot-C [Sophos]Heuristic: Suspicious File With Outbound Communica [Prevx1]Suspicious file [Panda]Trojan:Win32/SystemHijack.gen [Microsoft]Win32.SuspectCrc [Ikarus]W32/Horst.gen33 [F-Secure]suspicious Trojan/Worm [eSafe]
More aliases (105)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system\dllcache.exe File name: dllcache.exe
Size: 48.64 KB (48640 bytes)
MD5: 4c8f558ade7dd6320bda96ac54aba459
Detection count: 110
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: June 29, 2017
file.exe File name: file.exe
Size: 814.08 KB (814080 bytes)
MD5: 42e833dd8fb25b8ac7b0b19f4962ae6f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 8, 2016
%USERPROFILE%\M-505034039586930203940876\winsvc.exe File name: winsvc.exe
Size: 1.03 MB (1038848 bytes)
MD5: 2b49585f2811734ccd2811f1a7004c06
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-505034039586930203940876
Group: Malware file
Last Updated: November 5, 2019

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\dwmn.exe%APPDATA%\local.exe%APPDATA%\Microsoft\Windows\MMC\Explorer.exe%APPDATA%\Window Updates\winupdt3.exe%APPDATA%\winmgr.txt%WINDIR%\jodrive32.exe%WINDIR%\M-50502462522540258485045\winmgr.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Windows Update Service0%USERPROFILE%\P-7-78-8964-9648-3874

Related Posts

Loading...