Threat Search: 

ThreatExpert's Statistics for W32.IRCBot [Symantec]:

W32.IRCBot [Symantec] is also known as:
Threat AliasNumber of Incidents
W32/Sdbot.worm [McAfee]402
Mal/Generic-A [Sophos]212
Generic.dx [McAfee]169
Backdoor.IRC.Flood [PC Tools]144
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab]144
TROJ_BOTIRC.A [Trend Micro]144
Win32/IRCBot.worm.variant [AhnLab]135
Trojan.IRCBot [PC Tools]117
Backdoor:Win32/IRCbot [Microsoft]114
P2P-Worm.Win32.VB.dw [Kaspersky Lab]107
W32.Alcra.F [Symantec]104
Backdoor.IRCBot!sd6 [PC Tools]100
Troj/Multidr-FT [Sophos]96
Backdoor.IRCBot.DD [PC Tools]90
W32/Generic.m [McAfee]88
WORM_GAOBOT.DF [Trend Micro]88
Backdoor.Win32.Rbot.gen [Kaspersky Lab]74
W32/Virut.gen.a [McAfee]60
Win-Trojan/MircPack.574464 [AhnLab]60
Backdoor.Rbot [Ikarus]59
WORM_SDBOT.GAV [Trend Micro]56
W32/Virut.gen [McAfee]53
Backdoor.Win32.IRCBot [Ikarus]50
W32/Spybot.worm.gen [McAfee]50
IRC-Worm.Win32.Tedeto.a [Ikarus]48
P2P-Worm.Win32.Krepper.c [Kaspersky Lab]47
Virus.Win32.Virut.n [Kaspersky Lab]43
Worm.Akbot.Gen [PC Tools]43
WORM_SHAREBOT.A [Trend Micro]43
Win-Trojan/Xema.variant [AhnLab]41
Worm.Rbot.ABCC [PC Tools]41
Backdoor.Win32.SdBot.ts [Kaspersky Lab]36
I-Worm.Maslan.C [PC Tools]36
PE_MASLAN.C-O [Trend Micro]36
W32/Maslan!irc [McAfee]36
WORM_RBOT.GEN-1 [Trend Micro]36
Backdoor:Win32/Poebot.gen [Microsoft]35
Generic Downloader.s [McAfee]34
Mal/Behav-285 [Sophos]34
PE_VIRUT.AV [Trend Micro]34
VirTool.Win32.CeeInject [Ikarus]34
W32/Virut-W [Sophos]34
VirTool.Win32.DelfInject [Ikarus]31
Virus:Win32/Virut.AC [Microsoft]31
Win32.Virut.Gen.4 [PC Tools]31
Generic BackDoor [McAfee]30
Trojan-Downloader.VB.AWJ [PC Tools]30
W32/Sdbot.worm.gen.g [McAfee]30
Virus.Win32.Virut.av [Kaspersky Lab]29
Win32/Virut.B [AhnLab]28
Worm.P2P.Krepper [PC Tools]26
Backdoor.Win32.VanBot [Ikarus]25
Backdoor:Win32/Rbot.gen [Microsoft]25
Packed.Win32.Black.a [Kaspersky Lab]25
VirTool:Win32/CeeInject.gen!J [Microsoft]23
W32/IRCbot.gen.a [McAfee]22
BackDoor-AWQ [McAfee]21
VirTool:Win32/CeeInject.gen!A [Microsoft]21
W32/Sdbot.worm.gen.h [McAfee]21
W32/Vbbot [McAfee]21
Worm.P2P.Krepper.B [PC Tools]21
Worm.RBot.Gen.16 [PC Tools]21
Worm:Win32/Hamweq.A [Microsoft]21
Backdoor.IRCBot!sd5 [PC Tools]20
Trojan-Downloader.Win32.VB.bgd [Kaspersky Lab]20
Worm.PoeBot.KV [PC Tools]20
Backdoor.Win32.IRCBot.bad [Kaspersky Lab]19
Trojan.Win32.Buzus [Ikarus]19
Trojan:Win32/Ircbrute [Microsoft]18
W32/Vetor-A [Sophos]18
Win32.Virut.Gen [PC Tools]18
Backdoor.Win32.Mechbot.d [Kaspersky Lab]17
Trojan-Dropper.Win32.Sramler.e [Kaspersky Lab]17
W32/IRCbot.gen.f [McAfee]17
W32/Sdbot.worm.gen.n [McAfee]17
Worm:Win32/Spybot.CE [Microsoft]17
Backdoor.Mechbot [PC Tools]16
Backdoor.Win32.VanBot.dt [Kaspersky Lab]16
BKDR_VANBOT.NM [Trend Micro]16
not-a-virus.Keygen.Avast [Ikarus]16
P2P-Worm.Win32.Palevo.nxs [Kaspersky Lab]16
TROJ_DLOADER.PCR [Trend Micro]16
Trojan.Sramler.I [PC Tools]16
Trojan.Win32.Qhost.aei [Ikarus]16
Virus.Win32.Trojan [Ikarus]16
W32/Sdbot.worm.gen.ax [McAfee]16
Worm.Alcra.F [PC Tools]16
Worm.PoeBot.LC [PC Tools]16
Worm.Win32.Hamweq [Ikarus]16
Backdoor.Rbot!sd5 [PC Tools]15
Backdoor.Win32.Rbot.bng [Kaspersky Lab]15
PE_VIRUT.D [Trend Micro]15
Backdoor:Win32/Sdbot [Microsoft]14
PE_VIRUT.A [Trend Micro]14
Trojan-PWS.Win32.Delf [Ikarus]14
VirTool:Win32/DelfInject.gen!BE [Microsoft]14
VirTool:Win32/Injector.gen!B [Microsoft]14
W32/Bobax.worm.gen [McAfee]14
W32/Virut.a [McAfee]14
Win32/IRCBot.worm.Gen [AhnLab]14

W32.IRCBot [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
France59
China43
Sweden41
Israel33
Germany23
United Kingdom16
Canada15
Spain15
Russian Federation10
Italy7
Uzbekistan6
Portugal5
Brazil4
Egypt4
Saudi Arabia3
Austria2
Denmark2
Poland2
Slovakia2
Taiwan2
Thailand2
Argentina1
Australia1
Finland1
Honduras1
Japan1
Norway1
Romania1
Serbia and Montenegro1
Slovenia1
Ukraine1
Viet Nam1

W32.IRCBot [Symantec] is known to be created as:
%AppData%\br6657on.exe
%AppData%\csrss.exe
%AppData%\inetinfo.exe
%AppData%\lsass.exe
%AppData%\m\flec006.exe
%AppData%\microsoft\cd burning\autorun.exe
%AppData%\microsoft\svchost.exe
%AppData%\octopus.exe
%AppData%\services.exe
%AppData%\shieldmanager.exe
%AppData%\smss.exe
%AppData%\svchost.exe
%AppData%\thinstall\thinstallbuilder\400000d600003i\snapshot.exe
%AppData%\windowslive.exe
%AppData%\winlogon.exe
%CommonPrograms%\svchost.exe
%FontsDir%\alg.exe
%FontsDir%\unwise_.exe
%ProgramFiles%\_rejoice2009.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\client.exe
%ProgramFiles%\common files\system\klass.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\common files\system\mswvr32.exe
%ProgramFiles%\common files\system\svchosts.exe
%ProgramFiles%\common files\system\systemupgrade.exe
%ProgramFiles%\common files\system\win32update.exe
%ProgramFiles%\dsfsdfsd\nope.dll
%ProgramFiles%\internet explorer\iemate.dll
%ProgramFiles%\microsoft office\office\msohev.exe
%ProgramFiles%\microsoft office\office11\services.exe
%ProgramFiles%\microsoft office\winword.exe
%ProgramFiles%\mirc\irc bot\services.exe
%ProgramFiles%\mirc\irc bot\svchost.exe
%ProgramFiles%\outlook\outlook.exe
%ProgramFiles%\printdrv.exe
%ProgramFiles%\skypemate\skypemate.exe
%ProgramFiles%\tn_hacker\tn_hacker.exe
%ProgramFiles%\win32gl\msdnrespond.exe
%ProgramFiles%\windows nt\windows update\wuauclt.exe
%System%\___synmgr.exe
%System%\1.exe
%System%\123456.exe
%System%\abgsvc.exe
%System%\acmejo.exe
%System%\adobem.exe
%System%\afp.exe
%System%\agl23.exe
%System%\ago.exe
%System%\ahardi.exe
%System%\aicmirc.exe
%System%\aig.exe
%System%\aknnkkujs.exe
%System%\algr.exe
%System%\algs.exe
%System%\aolspy.exe
%System%\aomkpr.exe
%System%\app2.exe
%System%\apqjtr.exe
%System%\asdfsa.exe
%System%\asvsrv.exe
%System%\asvupdsa.exe
%System%\asvupdsv.exe
%System%\avgscr.exe
%System%\avgvupd.exe
%System%\avgvwsrv.exe
%System%\avgwsvcr.exe
%System%\bbriup.exe
%System%\bbwtrd.exe
%System%\bdmhxk.exe
%System%\bix.exe
%System%\bmghxm.exe
%System%\bootconfig.exe
%System%\bootk.exe
%System%\brfrlh.exe
%System%\bwtrp.exe
%System%\byaytb.exe
%System%\byjjebmo.exe
%System%\bzfpic.exe
%System%\cdmsn.exe
%System%\cdplayer.exe
%System%\cdrss.exe
%System%\cehmsj.exe
%System%\cfpxlyztf.exe
%System%\cftmon.exe
%System%\cgylcce.exe
%System%\chkntf.exe
%System%\cjpgauw.exe
%System%\cmd-bro-rlx.exe
%System%\cms.exe
%System%\cmskqq.exe
%System%\cmsksk.exe
%System%\cojjxzo.exe
%System%\cptfhx.exe
%System%\cpu.exe
%System%\crkxfyl.exe
%System%\crss.exe
%System%\csf.exe
%System%\csrs.exe
%System%\csrst.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).