1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: W32.Ircbot.NG Download Request

Attack: W32.Ircbot.NG Download Request

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.


A file download related to W32.Ircbot.NG has been blocked. No further action is required.

Additional Information

W32.Ircbot.NG is a worm that connects to remote CnC servers to download and install additional malware on the machine. It also opens backdoor on the infected machine.


  • Windows


No further action is required but you may wish to perform some of the following actions as a precautionary measure.
Run the Norton Power Eraser. (home users)
Run the Symantec Power Eraser. (business users)
Update your product definitions and perform a full system scan.
Submit suspicious files to Symantec for analysis.

If you believe that the signature is reported erroneously, please read the following:
Report a potential false positive to Symantec.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube