Backdoor

Backdoor.Win64.Meterpreter.cw (file analysis)

Malware Removal

The Backdoor.Win64.Meterpreter.cw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win64.Meterpreter.cw virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win64.Meterpreter.cw?


File Info:

crc32: C39988F7
md5: bde4be4b6141b29c4cd95da8ab7ffab3
name: BDE4BE4B6141B29C4CD95DA8AB7FFAB3.mlw
sha1: 4b49ecbc15efa643b08432b394a5d91d33cc1932
sha256: 5b9468610fd9202fc249242ea524a78b617fb1db1bd20191ffb3743f9ff6bfa7
sha512: 926d3d1279333634fa378e9babaab9665acba58dba44ff0ca24a88c75f73365ff7caabcbbf9daf9c200ccbab785dbc0fcd351139ea92f0391b7d26b05028de0d
ssdeep: 24576:fVwmAW+NNY8V4RCUM/Ep+3chPUcDqch332Ru8YTPxzh:fV6W17+0h9qch3Gu8Yj5h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2012-2021 Blizzard Entertainment Inc.
InternalName: Blizzard Battle.net App
FileVersion: 1.31.3.12685
CompanyName: Blizzard Entertainment
ProductName: Blizzard Battle.net App
ProductVersion: 1.31.3.12685
FileDescription: Blizzard Battle.net App
OriginalFilename: Battle.net.exe
Translation: 0x0000 0x04b0

Backdoor.Win64.Meterpreter.cw also known as:

MicroWorld-eScanTrojan.GenericKD.36425767
Qihoo-360Win64/HackTool.Meterpreter.HgIASP0A
McAfeeArtemis!BDE4BE4B6141
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win64.Meterpreter.m!c
SangforRiskware.Win32.Ymacco.AA5B
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36425767
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D22BD027
CyrenW32/Trojan.LZCB-9211
Paloaltogeneric.ml
KasperskyBackdoor.Win64.Meterpreter.cw
AlibabaBackdoor:Win64/Meterpreter.2833bc06
Ad-AwareTrojan.GenericKD.36425767
SophosGeneric PUA EL (PUA)
ComodoMalware@#5mgidqorlfgp
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeTrojan.GenericKD.36425767
EmsisoftTrojan.GenericKD.36425767 (B)
MAXmalware (ai score=80)
KingsoftWin32.Hack.Win64.cw.(kcloud)
GridinsoftTrojan.Win32.Meterpreter.oa
MicrosoftProgram:Win32/Ymacco.AA5B
ViRobotTrojan.Win32.Z.Meterpreter.1083904
ZoneAlarmBackdoor.Win64.Meterpreter.cw
GDataTrojan.GenericKD.36425767
AhnLab-V3Malware/Gen.RL_Reputation.R368804
BitDefenderThetaGen:NN.ZexaF.34608.cv0@aScLVqni
ALYacTrojan.GenericKD.36425767
VBA32Backdoor.Win64.Meterpreter
MalwarebytesMalware.AI.1245001786
TrendMicro-HouseCallTROJ_GEN.R002H0CC321
RisingBackdoor.Meterpreter!8.10216 (CLOUD)
IkarusWin32.SuspectCrc
eGambitUnsafe.AI_Score_67%
FortinetW64/Meterpreter.CW!tr.bdr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Backdoor.Win64.Meterpreter.cw?

Backdoor.Win64.Meterpreter.cw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment