Threat Search: 

ThreatExpert's Statistics for Backdoor.IRC.Bot [Symantec]:

Backdoor.IRC.Bot [Symantec] is also known as:
Threat AliasNumber of Incidents
Generic.dx [McAfee]33,151
TROJ_AGENT.ACSF [Trend Micro]31,858
BKDR_CIADOOR.EA [Trend Micro]30,456
Trojan.DL.VB.AAVI [PC Tools]29,159
Trojan.Win32.Agent.cmn [Kaspersky Lab]27,966
Trojan-Downloader.Win32.VB.bsa [Kaspersky Lab]21,960
Downloader.gen.a [McAfee]18,289
Trojan.Agent!sd5 [PC Tools]2,745
IRC/Flood.gen.e [McAfee]1,022
not-a-virus:Client-IRC.Win32.mIRC.601 [Kaspersky Lab]1,008
Trojan.Zapchast [PC Tools]938
BKDR_ZAPCHAST.AX [Trend Micro]910
Backdoor.Trojan [Symantec]826
IRC.Backdoor.Trojan [Symantec]810
TROJ_DLOADER.FXN [Trend Micro]810
Downloader-BJM [McAfee]769
Troj/Agent-GGQ [Sophos]769
Troj/Mirchack-A [Sophos]658
Trojan:Win32/Zapchast [Microsoft]658
TROJ_VB.CEO [Trend Micro]649
TrojanDownloader:Win32/VB [Microsoft]645
not-a-virus:Client-IRC.Win32.mIRC [Ikarus]547
Virus.Win32.VB.FXE [Ikarus]526
Generic BackDoor.f [McAfee]412
Backdoor:Win32/Rbot [Microsoft]403
Troj/Agent-GFL [Sophos]394
Worm.Ircbot [Ikarus]361
Win-Trojan/Xema.variant [AhnLab]324
Backdoor.IRC!sd5 [PC Tools]299
Trojan-Downloader.Win32.VB.dck [Kaspersky Lab]276
Win-Trojan/IRCHack.593262 [AhnLab]266
W32/Zipwire-A [Sophos]264
Backdoor.IRC!sd6 [PC Tools]258
W32/Sdbot.worm [McAfee]252
VBS/Ircbot [AhnLab]247
Generic PUP.x [McAfee]227
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab]226
Trojan.Win32.Agent [Ikarus]222
TrojanDownloader:Win32/Tonick.gen [Microsoft]214
Worm.Pizbot.A [PC Tools]201
Trojan-Spy.Win32.Banbra [Ikarus]180
Win-Trojan/Agent.839705 [AhnLab]174
Trojan-Downloader.VB!sd6 [PC Tools]140
Mal/EncPk-DV [Sophos]135
Win32/IRCBot.worm.variant [AhnLab]127
TrojanDownloader:Win32/VB.BK [Microsoft]124
Worm.Rbot.ABCC [PC Tools]104
Backdoor.Win32.IRCBot.jvw [Kaspersky Lab]99
BackDoor-DVR [McAfee]89
Troj/IRCBot-AET [Sophos]83
Backdoor.IRC [PC Tools]80
Trojan.Agent.DHWQ [PC Tools]80
Mal/Generic-A [Sophos]73
Backdoor:Win32/Agent [Microsoft]65
Mal/Bckdr-C, Mal/Inject-M [Sophos]57
Backdoor.Win32.IRCBot [Ikarus]56
Worm:Win32/Pizbot.gen [Microsoft]50
Mal/Inject-M [Sophos]41
BKDR_AGENT.XQB [Trend Micro]35
Generic BackDoor [McAfee]33
not-a-virus:Client-IRC.Win32.mIRC.601 [Ikarus]28
Troj/LdPinch-RT [Sophos]27
Backdoor.IRC.Lamin [Ikarus]26
VirTool:Win32/CeeInject.gen!R [Microsoft]25
MultiDropper-RY [McAfee]24
VirTool:Win32/VBInject.AB [Microsoft]23
VirTool:Win32/DelfInject.gen!N [Microsoft]22
Backdoor.Win32.Poison.wtd [Kaspersky Lab]21
Trojan.Buzus.KG [PC Tools]21
W32/Nirbot.worm [McAfee]19
Win-Trojan/Poison.139264.C [AhnLab]19
W32/Spybot.worm.gen [McAfee]18
W32/Spybot.worm.gen.a [McAfee]18
VirTool.Win32.CeeInject [Ikarus]17
Virus.Win32.Injector [Ikarus]17
Backdoor.Win32.Poison [Ikarus]16
BackDoor-DKI.gen.aj [McAfee]16
Troj/Poison-BN [Sophos]16
Backdoor.IRCBot!sd5 [PC Tools]15
Backdoor.Win32.IRCBot.cta [Kaspersky Lab]14
VirTool:Win32/CeeInject.gen!J [Microsoft]14
Worm.DR.Delf.AHJT [PC Tools]12
Backdoor:Win32/IRCbot.AN [Microsoft]11
Backdoor.Win32.Bifrose.aer [Kaspersky Lab]10
Backdoor.Win32.ForBot.am [Kaspersky Lab]10
Trojan-Downloader.VB!ct [PC Tools]10
Virus.Win32.Buzus [Ikarus]10
W32/IRCbot.gen.a [McAfee]10
WORM_SDBOT.GAV [Trend Micro]10
Backdoor.VanBot!sd6 [PC Tools]9
Backdoor.Win32.Bifrose.fms [Kaspersky Lab]9
Backdoor.Win32.mIRC-based.k [Kaspersky Lab]9
Backdoor.Win32.VanBot.wv [Kaspersky Lab]9
Backdoor.Win32.VanBot.xd [Kaspersky Lab]9
Backdoor:Win32/IRCbot.AF [Microsoft]9
Troj/Bckdr-QPX [Sophos]9
Trojan:Win32/Ircbrute [Microsoft]9
Trojan-Downloader.Win32.Agent.bl [Kaspersky Lab]9
TrojanDropper:Win32/VBInject.C [Microsoft]9
BackDoor-DVR.gen.a [McAfee]8

Backdoor.IRC.Bot [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation78
Germany26
Israel25
Sweden19
United Kingdom12
Italy10
Netherlands5
Spain5
Canada2
Australia1
Brazil1
France1
Poland1
Portugal1
Slovakia1
Switzerland1
Taiwan1
Thailand1

Backdoor.IRC.Bot [Symantec] is known to be created as:
%AppData%\nt.dll
%FontsDir%\svchost.exe
%Profiles%\no_love_6.exe
%ProgramFiles%\bifrost\asd.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\black\antivirus.exe
%ProgramFiles%\c\builder.exe
%ProgramFiles%\cam\cam.exe
%ProgramFiles%\coffin\server.exe
%ProgramFiles%\common files\system\ati.exe
%ProgramFiles%\common files\system\scvhost.exe
%ProgramFiles%\common files\system\system.exe
%ProgramFiles%\drivers\system.exe
%ProgramFiles%\microsoft office\office11\yofc.dll
%ProgramFiles%\microsoft office\winword.exe
%ProgramFiles%\microsoft\experience.exe
%ProgramFiles%\mirc\irc bot\services.exe
%ProgramFiles%\mirc\irc bot\svchost.exe
%ProgramFiles%\msns\msn.exe
%ProgramFiles%\system\server.exe
%ProgramFiles%\system-second\home.exe
%ProgramFiles%\update\msn.exe
%ProgramFiles%\windowsdll\windows.exe
%ProgramFiles%\xerox\xerox.exe
%System%\666\99.exe
%System%\access.exe
%System%\aheqm.com
%System%\bifrost\bosh.exe
%System%\bifrost\ksa.exe
%System%\bifrost\server.exe
%System%\bndmss.exe
%System%\bootcli.exe
%System%\bootconf.exe
%System%\bootconfig.exe
%System%\bootserver.exe
%System%\bootservice.exe
%System%\bootsfv.exe
%System%\bootsv.exe
%System%\chkdsker.exe
%System%\cisrv.exe
%System%\cisvr.exe
%System%\cleanmg.exe
%System%\clipsv.exe
%System%\coffin.exe
%System%\coffin\coffin.exe
%System%\cscripts.exe
%System%\csrhost.exe
%System%\csrsc.exe
%System%\csvhost.exe
%System%\cxdvnnxsv.exe
%System%\dcomcnf.exe
%System%\dllcache\rtsecar.exe
%System%\dllcache\servicesmsi.exe
%System%\dllcache\spoolms.exe
%System%\dllcache\winxptcp.exe
%System%\dllmon32.exe
%System%\drivers\bsobt.exe
%System%\drivers\bswbt.exe
%System%\drivers\csgf.exe
%System%\drivers\csrss.exe
%System%\drivers\ntndis.exe
%System%\drmupgd.exe
%System%\dvssvc.exe
%System%\dynsh32.dll
%System%\enule.exe
%System%\explorer.exe
%System%\explorer\explorer.exe
%System%\firefox.exe
%System%\fiwvugklc.exe
%System%\fontviewer.exe
%System%\gpreslt.exe
%System%\host.exe
%System%\ie4uini.exe
%System%\iexplore.exe
%System%\iexpresser.exe
%System%\igfxsrvc32.exe
%System%\initsvc.exe
%System%\iplogsec.exe
%System%\ipsec7.exe
%System%\isass.exe
%System%\lcss.exe
%System%\livemsngr.exe
%System%\lmhost.exe
%System%\loaderxp.exe
%System%\mclb32.dll
%System%\mcnbc.exe
%System%\mgt.exe
%System%\mmdmm.exe
%System%\msadvapi32.dll
%System%\msdts.exe
%System%\msmpserv.exe
%System%\msmsgs.exe
%System%\msmsnserv.exe
%System%\msmsnserver.exe
%System%\msnbooster.exe
%System%\msndebug.exe
%System%\msnhost.exe
%System%\msnhosts.exe
%System%\msnloader.exe
%System%\msnlvclient.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).