Home Malware Programs Worms W32.Ircbrute.E

W32.Ircbrute.E

Posted: March 30, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 6
First Seen: March 30, 2012
OS(es) Affected: Windows

W32.Ircbrute.E is a computer worm that tries to circulate through removable drives and open a back door on the infected computer by connecting to the certain website on TCP port 6667. Once executed, W32.Ircbrute.E replicates itself by creating the cerain files on all removable drives and runs when the drives are accessed. W32.Ircbrute.E also creates the certain registry entry so that it can run every time you start Windows. W32.Ircbrute.E creates the particular mutex named 'root_v_1' so that only one instance of the malware threat runs on the PC. Use a legitimate anti-virus program to remove W32.Ircbrute.E immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%DriveLetter%\autorun.inf File name: %DriveLetter%\autorun.inf
Mime Type: unknown/inf
Group: Malware file
%DriveLetter%\recycler\k-1-3542-4232123213-7676767-8888886\hn.exe File name: %DriveLetter%\recycler\k-1-3542-4232123213-7676767-8888886\hn.exe
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\recycler\k-1-3542-4232123213-7676767-8888886\desktop.ini File name: %DriveLetter%\recycler\k-1-3542-4232123213-7676767-8888886\desktop.ini
Mime Type: unknown/ini
Group: Malware file
%SystemDrive%\RECYCLER\k-1-3542-4232123213-7676767-8888886\Desktop.ini File name: %SystemDrive%\RECYCLER\k-1-3542-4232123213-7676767-8888886\Desktop.ini
Mime Type: unknown/ini
Group: Malware file
%SystemDrive%\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe File name: %SystemDrive%\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{23KLN5J0-4OPM-11WE-AAX5-24EF1F387232}\"StubPath" = "%SystemDrive%\RECYCLER\k-1-3542-4232123213-7676767-8888886\hn.exe"
Loading...