Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 20 October 2011

Remove Backdoor:Win32/IRCbot (Uninstall Guide)

Posted on 11:10 by Unknown
Backdoor:Win32/IRCbot is a Trojan horse that connects to an Internet Relay Chat (IRC) server, allows remote access to the infected system and eventually turns your computer into an advertising cash making machine. The Trojan has to be manually installed. It is transmitted via instant messaging software, Facebook, and malicious websites. Very often, Backdoor:Win32/IRCbot masquerades as picture and it even looks like a real picture but if you take a closer look, you'll see that it's an executable file. Here's an example of an infected file.

PIC67893549074533-JPG-www.facebook.com



PIC67893549074533-JPG-www.facebook.com.exe



If you hide extensions for known file types, there's a great chance you won't notice the difference. Besides, the infected executable loads a picture to dispel suspicion (not always). Upon execution, Backdoor:Win32/IRCbot drops a file into a users's Application data and Start Up folders, modifies Windows registry and attempts to configure the system to run malicious files automatically everytime Windows starts.

The payload program targets Facebook accounts, Windows Live Messenger, and Yahoo Messenger for further propagation. It simply injects a few words (example: ""hahdhauhahaaha did you see this??") and malicious URL into your private messages and your Facebook wall. It then hides IMs chat history. Furthermore, Backdoor:Win32/IRCbot changes the home page to http://domredi.com/1/ in Internet Explorer. It then randomly redirects Internet Explorer to other shady websites. The following website were identified:
  • easynetseek.com
  • go2article.info
  • articleslot.info
  • skyarticle.net
  • diggarticle.com
  • digitword.com
  • qoolsearch.info
They all look messed up, mostly free article directories and spammy search engines.






Thankfully, you can restore your default home page and stop the annoying redirects without any problems. You can remove Backdoor:Win32/IRCbot manually as well, if you feel confident working with the Registry Editor and you know exactly which files are infected. However, please note that this Trojan may drop malicious files into different folders and download additional malware onto your computer. We strongly recommend you to use anti-malware software to remove this Trojan horse and associated malware from your computer. If you need help removing Backdoor:Win32/IRCbot, including all variants of this infection, please leave a comment below or just email use. Good luck and be safe online!


Backdoor:Win32/IRCbot removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this backdoor Trojan from your computer.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

2. Go to Tools → Internet Options. Select General tab and click Use default button or enter your own website, e.g. google.com instead of http://domredi.com/1/. Click OK to save the changes. And that's about it.




Associated Backdoor:Win32/IRCbot files and registry values:

Files:
  • C:\Documents and Settings\[UserName]\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].exe
  • C:\Documents and Settings\[UserName]\Start Menu\Programs\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
Share this information with your friends:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Trojans | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • WebCake Adware Removal Guide
    If you’re reading this it is very likely that your computer is infected with WebCake adware which displays extremely obnoxious and intrusiv...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ▼  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ▼  October (21)
      • Remove Rattlingsearchsystem.com (Uninstall Guide)
      • Remove Signalsearchsystem.com (Uninstall Guide)
      • Colossalsearchsystem.com (Uninstall Guide)
      • Remove Raresearchsystem.com (Uninstall Guide)
      • Remove Uncommonsearchsystem.com (Uninstall Guide)
      • How to Remove System Security 2011 (Uninstall Guide)
      • Remove Wickedsearchsystem.com (Uninstall Guide)
      • Remove Backdoor:Win32/IRCbot (Uninstall Guide)
      • How to Remove AV Protection Online (Uninstall Guide)
      • Remove Unusualsearchsystem.com (Uninstall Guide)
      • Remove Swellsearchsystem.com (Uninstall Guide)
      • How to Remove Antivirus XP Hard Disk Repair (Unins...
      • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
      • How to Remove System Restore (Rogue Software)
      • How to Remove Cloud Protection (Uninstall Guide)
      • How to Remove Guard Online (Uninstall Guide)
      • Steve Jobs Alive! Spam, Win32/Waledac.C Trojan and...
      • Use Priv3 to Prevent Being Tracked by Social Networks
      • How to Remove AV Guard Online (Uninstall Guide)
      • Volmgr.exe, volmgr.dll: Trojan.Plongo and Google/B...
      • How to Remove Security Guard 2012 (Uninstall Guide)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile