Backdoor

Backdoor.NetMail malicious file

Malware Removal

The Backdoor.NetMail is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.NetMail virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor.NetMail?


File Info:

name: 03EAC2FFA428488B4A67.mlw
path: /opt/CAPEv2/storage/binaries/659f1c97a3294046a9a2a148d2d2419fc363a5375406850d859ba971c8b84ca6
crc32: E07121CE
md5: 03eac2ffa428488b4a6772462cc5cc6c
sha1: 3e88dc8b6fc0d48fe94f203040cf47fb8c78259c
sha256: 659f1c97a3294046a9a2a148d2d2419fc363a5375406850d859ba971c8b84ca6
sha512: e6f9960fb1903813524b9f3b23e570258e8d1f8fee28ae3ec3c7b49af3d010cb790b12353f5d6138e8220fa0bc2c70c29d455923e9a041cd32c9fe0ac4b48258
ssdeep: 12288:i2ToLD2QfWUEknSsmjj/UVF4TsSTEP/NkpflHTjMVJK1P5aEL3MK0Kyhx:ikuPfWsnnw/UV+sSTEtKMVcRadY2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135254B3BAF8A9136D96234FC8D9FC0D5940939312C485B87FF919F0D7E76652232A983
sha3_384: 4a590bc1888549a6d3b9daffe96470dd0cca454916260940433d9a1cbcd4a2307994603a2d7a846aec8b8bc39d2ad8ff
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.NetMail also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.46553
FireEyeGeneric.mg.03eac2ffa428488b
McAfeeGenericRXIE-DJ!03EAC2FFA428
MalwarebytesMalware.AI.693497512
ZillyaTrojan.Banker.Win32.53195
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bfe9d1 )
K7GWSpyware ( 004bfe9d1 )
Cybereasonmalicious.fa4284
ArcabitTrojan.Doina.DB5D9
BitDefenderThetaGen:NN.ZelphiF.36164.8GW@auv89co
CyrenW32/Banker.V.gen!Eldorado
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyBackdoor.Win32.NetMail.a
BitDefenderGen:Variant.Doina.46553
NANO-AntivirusTrojan.Win32.NetMail.cndhca
AvastWin32:Trojan-gen
TencentBackdoor.Win32.NetMail.ha
TACHYONTrojan/W32.DP-Agent.988160
EmsisoftGen:Variant.Doina.46553 (B)
F-SecureTrojan.TR/Zusy.9881605548
DrWebTrojan.DownLoader4.61273
VIPREGen:Variant.Doina.46553
TrendMicroBackdoor.Win32.NETMAIL.SMTH
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.dh
Trapminesuspicious.low.ml.score
SophosTroj/Agent-BCNT
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/NetMail.a
GoogleDetected
AviraTR/Zusy.9881605548
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
MicrosoftTrojan:Win32/Dorv.B!rfn
ZoneAlarmBackdoor.Win32.NetMail.a
GDataWin32.Trojan-Stealer.Banker.AK
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.NetMail.C3359984
VBA32Backdoor.NetMail
ALYacGen:Variant.Doina.46553
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Dtcontx.I
ZonerTrojan.Win32.88740
TrendMicro-HouseCallBackdoor.Win32.NETMAIL.SMTH
YandexTrojan.GenAsa!Dt9naGN/FsA
IkarusTrojan-Spy.Zbot
FortinetW32/Banker.WGA!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Backdoor.NetMail?

Backdoor.NetMail removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment