Backdoor

How to remove “Backdoor:Win32/Nethief.5_1”?

Malware Removal

The Backdoor:Win32/Nethief.5_1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Nethief.5_1 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Nethief.5_1?


File Info:

crc32: CCFA1BFF
md5: 4c020b4fe1a72de86374566a03b1d708
name: 4C020B4FE1A72DE86374566A03B1D708.mlw
sha1: 2282c58cc32083082db1a4cfde19eb8b6d1922e4
sha256: eb1205505c82b243382209326bdec67568a8055b972a694668a743aba5734c8a
sha512: 0199559d63cec0358de17a10b73f70fdd9679c5617a78c1a722176e49efb5e0bc1ce8706229e29b420e010236dd32044dcb5b576b733597496795f8e311de7d8
ssdeep: 384:kixs7TiSnQfUdXpjt8ywyajFVgziVGrq73Ql03No1eKKwStiU8urVdbOcGMCq:k/viQQ8xpjt8ysRVggGrqDl3No1eKKwy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Nethief.5_1 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00001f0d1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Nethief.51
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.bmHfrj6JM2dby
CylanceUnsafe
ZillyaBackdoor.Nethief.Win32.200
SangforTrojan.Win32.Reconyc.fjgw
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaBackdoor:Win32/Reconyc.1327bc84
K7GWTrojan ( 00001f0d1 )
Cybereasonmalicious.fe1a72
CyrenW32/Nethief.CFYH-6436
SymantecBackdoor.NetThief
ESET-NOD32Win32/Nethief.51
APEXMalicious
AvastWin32:Nethief-T [Trj]
ClamAVWin.Trojan.Nethief-102
KasperskyTrojan.Win32.Reconyc.fjgw
BitDefenderGen:Trojan.Heur.bmHfrj6JM2dby
NANO-AntivirusTrojan.Win32.Nethief.gazx
ViRobotBackdoor.Win32.Nethief.22407
MicroWorld-eScanGen:Trojan.Heur.bmHfrj6JM2dby
TencentMalware.Win32.Gencirc.10c85c92
Ad-AwareGen:Trojan.Heur.bmHfrj6JM2dby
SophosMal/Generic-R + Troj/Nethief-51
ComodoBackdoor.Win32.Nethief.51@1nvd
BitDefenderThetaAI:Packer.ED43D8931D
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_NETHIEF.51
McAfee-GW-EditionBehavesLike.Win32.Ransomware.mc
FireEyeGeneric.mg.4c020b4fe1a72de8
EmsisoftGen:Trojan.Heur.bmHfrj6JM2dby (B)
JiangminBackdoor/Nethief.p.Server
WebrootW32.Trojan.Gen
AviraBDS/Nethief.51.B
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3D93B
MicrosoftBackdoor:Win32/Nethief.5_1
ArcabitTrojan.Heur.bmHfrj6JM2dby
GDataGen:Trojan.Heur.bmHfrj6JM2dby
AhnLab-V3Trojan/Win32.Pwstealer.R37860
McAfeegeneric!bg.b
MAXmalware (ai score=85)
VBA32Backdoor.Nethief
MalwarebytesMalware.AI.3194790224
PandaBck/Nethief.AD
TrendMicro-HouseCallBKDR_NETHIEF.51
RisingBackdoor.Win32.Nethief.s (CLASSIC)
YandexTrojan.GenAsa!eGDSXGFZW2c
IkarusBackdoor.Win32.Ceckno
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Nethief.K!tr.bdr
AVGWin32:Nethief-T [Trj]
Qihoo-360Win32/TrojanSpy.Reconyc.HwsB6AwB

How to remove Backdoor:Win32/Nethief.5_1?

Backdoor:Win32/Nethief.5_1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment