Backdoor

What is “Backdoor:Win32/Nethief.Y”?

Malware Removal

The Backdoor:Win32/Nethief.Y is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Nethief.Y virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Nethief.Y?


File Info:

name: 22C42278DB621254692F.mlw
path: /opt/CAPEv2/storage/binaries/3b19605e25980f25f3dc25ff12a0e25520e4ef46c00e55a1cafb30625f2d7871
crc32: A70B3B9B
md5: 22c42278db621254692f194c2e66bfb6
sha1: 405fde83122c27d3b2afdeb96604e0fe6e0682bc
sha256: 3b19605e25980f25f3dc25ff12a0e25520e4ef46c00e55a1cafb30625f2d7871
sha512: 7db51adf51ae7c3fdb5b74ff3e54e1dd534ee022da4bbe85202e063064bb375c38fb691ad36bc799452610ffad3065e6d8034268083ed8d267b89f7743e46eba
ssdeep: 98304:cP4gBgXb+mXJ98UEKEOjh74VUFVbSdf/FSnP7IPqejauTsLrI:O4gBgL+wJ9844E23F8P73ssLrI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15216F0112AA7D435F2682032CD5EB2FDE151AF319F179A833AC03D2969739E16F36316
sha3_384: cab83af8ee0ffecbc7429dd78291e87bb2663eeef3d87bea7a3064d0f153cd18035e6b65849dae22dc93bc461f87b31f
ep_bytes: e8cac10000e978feffff8bff558bec6a
timestamp: 2022-10-21 15:10:29

Version Info:

Comments:
CompanyName:
FileDescription: Windows Skype
FileVersion: 79.1
InternalName: Windows Skype
LegalCopyright: 版权所有(C) 2022
LegalTrademarks:
OriginalFilename: Windows Skype.exe
PrivateBuild:
ProductName: Windows Skype
ProductVersion: 80.0
SpecialBuild:
Translation: 0x0804 0x04b0

Backdoor:Win32/Nethief.Y also known as:

BkavW32.Common.B02B83C5
LionicTrojan.Win32.Nethief.4!c
MicroWorld-eScanGen:Variant.Fragtor.155561
FireEyeGen:Variant.Fragtor.155561
McAfeeArtemis!22C42278DB62
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3937428
SangforBackdoor.Win32.Nethief.Vcn3
K7AntiVirusTrojan ( 005962701 )
AlibabaBackdoor:Win32/Nethief.10b583ac
K7GWTrojan ( 005962701 )
ArcabitTrojan.Fragtor.D25FA9
CyrenW32/Nethief.A.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQGE
APEXMalicious
BitDefenderGen:Variant.Fragtor.155561
NANO-AntivirusTrojan.Win32.Kryptik.jtlgsw
AvastWin32:Nethief-H [Trj]
TencentMalware.Win32.Gencirc.13ad8cb0
EmsisoftGen:Variant.Fragtor.155561 (B)
F-SecureTrojan.TR/Crypt.Agent.hycca
DrWebTrojan.DownLoader45.26704
VIPREGen:Variant.Fragtor.155561
TrendMicroTROJ_GEN.R002C0DGR23
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.hycca
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftBackdoor:Win32/Nethief.Y
GDataGen:Variant.Fragtor.155561
CynetMalicious (score: 99)
ALYacGen:Variant.Fragtor.155561
MAXmalware (ai score=88)
MalwarebytesGeneric.HackTool.RiskWare.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGR23
RisingDownloader.FakeTG!1.E381 (CLASSIC)
IkarusBackdoor.Win32.Nethief
FortinetW32/Kryptik.HQGE!tr
AVGWin32:Nethief-H [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Nethief.Y?

Backdoor:Win32/Nethief.Y removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment