Backdoor

What is “Backdoor.Win32.NetWiredRC.lac”?

Malware Removal

The Backdoor.Win32.NetWiredRC.lac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.NetWiredRC.lac virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
kingshakes.linkpc.net

How to determine Backdoor.Win32.NetWiredRC.lac?


File Info:

crc32: 4B6E9184
md5: 5db95b04df766972edbf3af11dd1d461
name: 5DB95B04DF766972EDBF3AF11DD1D461.mlw
sha1: b344d170ff873c945ed029a8e0ffe05d72efa337
sha256: 2cda176ce221ab580e6d9bbebc4333fa2156c33c9d4e3666c38eba656e13ef6b
sha512: 3c4da07170e7ffc6c6b597118944db39c8c874f4847a501c2cf72f74f1a35cf8be6b2f959e389ced5048d5330aae6a6dbcd7991883c83c4dad1bb1ba6759886c
ssdeep: 3072:jOzPcXa+ND32eioGHlz8rnAE0HCXh0edLvEhYMjMqqDvFf:jOTcK+NrRioGHlz8rz0i/2zQqqDvFf
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.NetWiredRC.lac also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.684266
McAfeeGenericRXKH-LK!5DB95B04DF76
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Razy.684266
K7GWTrojan ( 005485311 )
K7AntiVirusTrojan ( 005485311 )
ArcabitTrojan.Razy.DA70EA
CyrenW32/S-6c6572b7!Eldorado
SymantecInfostealer
APEXMalicious
ClamAVWin.Dropper.NetWire-8025706-0
KasperskyBackdoor.Win32.NetWiredRC.lac
NANO-AntivirusTrojan.Win32.Wirenet.hlbptg
RisingBackdoor.NetWire!1.C98D (CLASSIC)
Ad-AwareGen:Variant.Razy.684266
EmsisoftGen:Variant.Razy.684266 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebBackDoor.Wirenet.557
ZillyaTrojan.Weecnaw.Win32.761
TrendMicroBackdoor.Win32.NETWIRED.SMK
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
MaxSecureTrojan.Malware.102170081.susgen
FireEyeGeneric.mg.5db95b04df766972
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.NetWiredRC.bld
AviraTR/Spy.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.NetWiredRC
GridinsoftRansom.Win32.Wacatac.oa!s1
MicrosoftTrojan:Win32/Netwire.AA!MTB
ZoneAlarmBackdoor.Win32.NetWiredRC.lac
GDataWin32.Trojan.Netwire.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_NetWiredRC.R342610
VBA32BScope.TrojanSpy.Loyeetro
ALYacGen:Variant.Razy.684266
TACHYONTrojan/W32.NetWiredRC.164352
MalwarebytesBackdoor.Quasar
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
TrendMicro-HouseCallBackdoor.Win32.NETWIRED.SMK
YandexTrojan.GenAsa!DOgbQEDHp9A
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_71%
FortinetW32/Ulise.103681!tr
BitDefenderThetaGen:NN.ZexaF.34670.kCW@amsq2rh
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.4df766
AvastWin32:RATX-gen [Trj]
Qihoo-360HEUR/QVM20.1.CB1F.Malware.Gen

How to remove Backdoor.Win32.NetWiredRC.lac?

Backdoor.Win32.NetWiredRC.lac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment