Backdoor

Backdoor.Netmail removal

Malware Removal

The Backdoor.Netmail is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Netmail virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor.Netmail?


File Info:

name: 109EFBD6CB1C5F42058A.mlw
path: /opt/CAPEv2/storage/binaries/e76e957be27abbebe7f9f24be6eac1d1a42c17404009d844e53a6f966b899563
crc32: 709F4E72
md5: 109efbd6cb1c5f42058a67d84dc10ea6
sha1: 526b06ee033f560bb84a14c6722cbda57f957617
sha256: e76e957be27abbebe7f9f24be6eac1d1a42c17404009d844e53a6f966b899563
sha512: 04986cddae5a1d0d400064a8cefea10fd0bce98a3c3d49b980091d0e7bff50b2edbb7dc9fd169e80a88dc01c606f1fd876b02666e7f78866db1d261e5ecc343b
ssdeep: 12288:i2ToLD2QfWUEknSsmjj/UVF4T3Spr9+kTjMVJK1P5aEL3+fvyhx:ikuPfWsnnw/UV+3SprPMVcRap2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE253B3BAF8AA136D96234BC8C5FC0D5940939312C585B87FF919F0D7E76653232A983
sha3_384: ede89fceec91a79251df574924f6956dc26dfcfe9cd454ba6194e7179091ec5d29f16bcbf599226449e78cd11ca39ed8
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Netmail also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NetMail.tpTN
MicroWorld-eScanGen:Variant.Doina.46553
FireEyeGeneric.mg.109efbd6cb1c5f42
CAT-QuickHealBackdoor.Netmail
McAfeeGenericRXIE-DJ!109EFBD6CB1C
Cylanceunsafe
ZillyaTrojan.Banker.Win32.53195
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bfe9d1 )
AlibabaMalware:Win32/km_2e2d0662.None
K7GWSpyware ( 004bfe9d1 )
Cybereasonmalicious.6cb1c5
BitDefenderThetaGen:NN.ZelphiF.36250.8GW@auv89co
CyrenW32/Banker.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyBackdoor.Win32.NetMail.a
BitDefenderGen:Variant.Doina.46553
NANO-AntivirusTrojan.Win32.NetMail.cndhca
AvastWin32:Trojan-gen
RisingRansom.Blocker!8.12A (TFE:4:iWNbawThGVF)
TACHYONTrojan/W32.DP-Agent.988160
SophosTroj/Agent-BCNT
F-SecureTrojan.TR/Zusy.9881605548
DrWebTrojan.DownLoader4.61273
VIPREGen:Variant.Doina.46553
TrendMicroBackdoor.Win32.NETMAIL.SMTH
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.dh
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Doina.46553 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.Banker.AK
JiangminBackdoor/NetMail.a
GoogleDetected
AviraTR/Zusy.9881605548
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Doina.DB5D9
ViRobotTrojan.Win.Z.Netmail.988160.IEN
ZoneAlarmBackdoor.Win32.NetMail.a
MicrosoftTrojan:Win32/Dorv.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.NetMail.C3359984
VBA32Backdoor.NetMail
ALYacGen:Variant.Doina.46553
MAXmalware (ai score=80)
MalwarebytesMalware.AI.693497512
PandaTrj/Dtcontx.I
ZonerTrojan.Win32.88740
TrendMicro-HouseCallBackdoor.Win32.NETMAIL.SMTH
TencentBackdoor.Win32.NetMail.ha
YandexTrojan.GenAsa!Dt9naGN/FsA
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banker.WGA!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Netmail?

Backdoor.Netmail removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment