Backdoor

Backdoor.Win32.NetMail.a removal

Malware Removal

The Backdoor.Win32.NetMail.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.NetMail.a virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor.Win32.NetMail.a?


File Info:

name: 4AF46C7C376F352C87C4.mlw
path: /opt/CAPEv2/storage/binaries/c1ec4db552fec580af37397cfe7c7e2c4e3d784839738fcde954d6b9d6dee284
crc32: 86D99009
md5: 4af46c7c376f352c87c40817e285044f
sha1: 46920a49c3299f8cc53d094cd3611e7595dd42eb
sha256: c1ec4db552fec580af37397cfe7c7e2c4e3d784839738fcde954d6b9d6dee284
sha512: 6687b3f6d9f5a52bf13e3c11ae9208877c28b2c47a2d624d76f6a0485f7e2230db1642734239ec3488e83fa9e775097369c4ff612a3e88e298e0ab35ff33e7ae
ssdeep: 12288:i2ToLD2QfWUEknSsmjj/UVF4TPSiggK/TjMVJK1P5aEL3Lzyhx:ikuPfWsnnw/UV+PSigbMVcRaI2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102253B3BAF8AD136D96234BC4C9FC1D5940939312C485B87FF919F0D7E76652232A983
sha3_384: c8b3e445a4bb97821cdff08188f4cc6d07693aabb05756887f991f9041006e0b74d800efb35ef00ba2551f3146c60c6c
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Win32.NetMail.a also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoader4.61273
MicroWorld-eScanGen:Variant.Doina.46553
FireEyeGeneric.mg.4af46c7c376f352c
McAfeeGenericRXIE-DJ!4AF46C7C376F
MalwarebytesMalware.AI.693497512
VIPREGen:Variant.Doina.46553
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bfe9d1 )
BitDefenderGen:Variant.Doina.46553
K7GWSpyware ( 004bfe9d1 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZelphiF.36164.8GW@auv89co
CyrenW32/Banker.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyBackdoor.Win32.NetMail.a
NANO-AntivirusTrojan.Win32.NetMail.cndhca
AvastWin32:Trojan-gen
TencentBackdoor.Win32.NetMail.ha
EmsisoftGen:Variant.Doina.46553 (B)
F-SecureTrojan.TR/Zusy.9881605548
ZillyaTrojan.Banker.Win32.53195
TrendMicroBackdoor.Win32.NETMAIL.SMTH
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.dh
Trapminesuspicious.low.ml.score
SophosTroj/Agent-BCNT
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.Banker.AK
JiangminBackdoor/NetMail.a
GoogleDetected
AviraTR/Zusy.9881605548
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Doina.DB5D9
ZoneAlarmBackdoor.Win32.NetMail.a
MicrosoftTrojan:Win32/Dorv.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.NetMail.C3359984
VBA32Backdoor.NetMail
ALYacGen:Variant.Doina.46553
TACHYONTrojan/W32.DP-Agent.988160
Cylanceunsafe
PandaTrj/Dtcontx.I
ZonerTrojan.Win32.88740
TrendMicro-HouseCallBackdoor.Win32.NETMAIL.SMTH
RisingRansom.Blocker!8.12A (TFE:4:iWNbawThGVF)
YandexTrojan.GenAsa!Dt9naGN/FsA
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banker.WGA!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Backdoor.Win32.NetMail.a?

Backdoor.Win32.NetMail.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment