How to Prevent and Remove the
Backdoor.Win32.IRCBot.rgs
|
| # | Filename(s) | File Size |
| 1 |
%Windir%\cwdrive32.exe [file and pathname of the sample #1] |
118,784 bytes |
- Note:
- %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
b. Memory Modifications
-
There was a new process created in the system:
| Process Name | Process Filename | Main Module Size |
| cwdrive32.exe | %Windir%\cwdrive32.exe | 339,968 bytes |
c. Registry Modifications
- The following Registry Keys were created:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
- The newly created Registry Values are:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
- Microsoft Driver Setup = "%Windir%\cwdrive32.exe"
so that cwdrive32.exe runs every time Windows starts
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- Microsoft Driver Setup = "%Windir%\cwdrive32.exe"
so that cwdrive32.exe runs every time Windows starts
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
d. Other details
-
The following ports were open in the system:
| Port | Protocol | Process |
| 1055 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1057 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1233 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1234 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1235 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1236 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1237 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1238 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1239 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1240 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1241 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1242 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1243 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1244 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1245 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1246 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1247 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1248 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1249 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1250 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1251 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1252 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1253 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1254 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1255 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1256 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1257 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1258 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1259 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1260 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1261 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1262 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1263 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1264 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1265 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1266 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1267 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1268 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1269 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1270 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1271 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1272 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1273 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1274 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1275 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1276 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1277 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1278 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 1279 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2231 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2232 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2233 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2234 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2235 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2236 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2237 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2238 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2239 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2240 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2241 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2242 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2243 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2244 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2245 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2246 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2247 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2248 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2249 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2250 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2251 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2252 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2253 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2254 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2255 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2256 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2257 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2258 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2259 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2260 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2261 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2262 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2263 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2264 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2265 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2266 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2267 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2268 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2269 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2270 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2271 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2272 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2273 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2274 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
| 2275 | TCP | cwdrive32.exe (%Windir%\cwdrive32.exe) |
-
There were registered attempts to establish connection with the remote hosts. The connection details are:
| Remote Host | Port Number |
| 112.78.112.208 | 80 |
| 218.85.133.201 | 80 |
| 204.45.74.106 | 6682 |
-
The data identified by the following URLs was then requested from the remote web server:
- http://www.nippon.to/cgi-bin/prxjdg.cgi
- http://www.cooleasy.com/cgi-bin/prxjdg.cgi
3. How-to's
a. How to prevent the Backdoor.Win32.IRCBot.rgs ?
Please update the policy basic knowledge of Sax2 in time, Once Ax3soft sax2 detects the communication of these trojans, it will break them and ensure your network & business security.
b. How to Remove the Backdoor.Win32.IRCBot.rgs Manually?
Step 1 : Use Windows Task Manager to Remove Backdoor.Win32.IRCBot.rgs Processes
cwdrive32.exe
Step 2 : Use Registry Editor to Remove
Backdoor.Win32.IRCBot.rgs Registry Values
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
Microsoft Driver Setup = "%Windir%\cwdrive32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Microsoft Driver Setup = "%Windir%\cwdrive32.exe"
Step3: Detect and Delete Other Backdoor.Win32.IRCBot.rgs Files
%Windir%\cwdrive32.exe
[file and pathname of the sample #1]
c. How to Remove these trojans Instantly?
Manual removal is a difficult process and it is not recommend unless you are an expert in this field. Therefore, you best defense is to download and install a reliable anti-spyware program to scan spyware on your machine. In order to detect computer threats in the easiest and fastest way possible, we advised trying the Malwarebytes' Anti-Malware, it is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start. visit http://www.ids-sax2.com/Malwarebytes-Anti-Malware.htm and download Malwarebytes' Anti-Malware to help you.
4. Appendix
For more information, please visit http://www.ids-sax2.com/ComputerSecurityNewsletter.htm