1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: W32 IRCBot NG Activity 2

System Infected: W32 IRCBot NG Activity 2

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

W32.Ircbot.NG command and control communication has been blocked. It is recommended to scan your system.

Additional Information

W32.Ircbot.NG is a trojan that connects to remote CnC servers to download and install additional malware on the machine. It also opens backdoor on the infected machine.

Affected

  • Windows

Response

No further action is required but you may wish to perform some of the following actions as a precautionary measure.
Run the Norton Power Eraser. (home users)
Run the Symantec Power Eraser. (business users)
Update your product definitions and perform a full system scan.
Submit suspicious files to Symantec for analysis.

If you believe that the signature is reported erroneously, please read the following:
Report a potential false positive to Symantec.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube