Backdoor

Backdoor:Win32/Netsnake.A removal instruction

Malware Removal

The Backdoor:Win32/Netsnake.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Netsnake.A virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Harvests information related to installed mail clients
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Netsnake.A?


File Info:

crc32: 15DB8D70
md5: a5b8c7e5610ea13df158b526d907a835
name: A5B8C7E5610EA13DF158B526D907A835.mlw
sha1: 07f765d4cb203b226e2acf63fd35fe50c68f9a12
sha256: 114b618592b601d2b40126b1c2c207152d6ef5a230a024c48240d14ef3aff9b6
sha512: 160d94b8aa3aaa1f463a3609e00e11d9959be836ac6fbe37db875ff2047ed028a3feb09efa568aba8c7f3d556340d2349c34eeb8933723779fe58cebe1a6c4ac
ssdeep: 1536:rs0yl3rY55+MyCEzCgMrFlTBOjKBXoBi4i4kwsqTivIYDBm3l59:Yjli5+u5zUw4vOQYDBmV5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1993-1998
InternalName: Internat - exe
FileVersion: 4.90.1000.0
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments: WIN32 Network Interface Service Process
ProductName: Microsoft(R) Windows NT(R) Operating System
SpecialBuild:
ProductVersion: 4.90.1000.0
FileDescription: Internat MFC Application
OriginalFilename: Internat.EXE
Translation: 0x0409 0x04b0

Backdoor:Win32/Netsnake.A also known as:

K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebBackDoor.PowerSpider
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.33500689
CylanceUnsafe
ZillyaBackdoor.Netsnake.Win32.27
SangforBackdoor.Win32.Netsnake.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.5610ea
CyrenW32/SysVenFak.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Netsnake.A
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Netsnake.a
BitDefenderTrojan.GenericKD.33500689
NANO-AntivirusTrojan.Win32.Netsnake.fuwt
MicroWorld-eScanTrojan.GenericKD.33500689
TencentMalware.Win32.Gencirc.114cecac
Ad-AwareTrojan.GenericKD.33500689
SophosMal/Generic-R + Troj/Bdoor-AKM
ComodoBackdoor.Win32.Netsnake.A@3nhb
BitDefenderThetaGen:NN.ZexaF.34770.fm1faWdu2Apj
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroBKDR_NETSNAKE.A
FireEyeGeneric.mg.a5b8c7e5610ea13d
EmsisoftTrojan.GenericKD.33500689 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/NetSnake
AviraBDS/Netsnake.A
eGambitUnsafe.AI_Score_76%
MicrosoftBackdoor:Win32/Netsnake.A
ArcabitTrojan.Generic.D1FF2E11
GDataTrojan.GenericKD.33500689
TACHYONBackdoor/W32.Netsnake.84556
McAfeeBackDoor-AKM
MAXmalware (ai score=89)
VBA32Backdoor.Netsnake
MalwarebytesMalware.AI.2434978312
PandaGeneric Malware
TrendMicro-HouseCallBKDR_NETSNAKE.A
RisingBackdoor.Netsnake.aj (CLASSIC)
YandexTrojan.GenAsa!5hkmilp+tcM
IkarusTrojan.Win32.NetSnake
FortinetW32/Generic.AC.404237
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Snake.HxEAEpsA

How to remove Backdoor:Win32/Netsnake.A?

Backdoor:Win32/Netsnake.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment