Backdoor

About “Backdoor:Win32/NetThief” infection

Malware Removal

The Backdoor:Win32/NetThief is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/NetThief virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Backdoor:Win32/NetThief?


File Info:

crc32: 7B0C5B6F
md5: 81e8cabc30f873716bc2a0ac1429d683
name: NetThief.exe
sha1: 172f10e95e34fc381cfdc09a676aaf969c91e652
sha256: 223d5ea3fa861192fcec13bcb9d121117f41316c80445b827f9f1650805a61b1
sha512: 2c5f9f22ebd6b499fafd21d494cfa952f2c7982740b54621f97397f10ff928887f5bc6658f4817f22112ccf1448b74956a130aa2480f2aca1ebe548a346974ca
ssdeep: 12288:eXJAJPX2IEGpzK6FSkFvUt0DZI/CndxGNzZvGNjz2g:8AJPXh5pzvqV/C/yxGpn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2005
InternalName: NetThief
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NetThief x5e94x7528x7a0bx5e8f
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: NetThief Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: NetThief.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/NetThief also known as:

BkavW32.Clod60c.Trojan.212b
MicroWorld-eScanTrojan.Generic.1624522
nProtectTrojan.Generic.1624522
CAT-QuickHeal(Suspicious) – DNAScan
McAfeeArtemis!81E8CABC30F8
K7AntiVirusBackdoor ( 519f46130 )
K7GWBackdoor ( 0009570e1 )
NANO-AntivirusTrojan.Win32.Visel.brosii
F-ProtW32/Backdoor2.EPOY
SymantecBackdoor.Trojan
NormanObfuscated.AI!genr
AvastWin32:Nethief-AH [Trj]
KasperskyBackdoor.Win32.Visel.age
BitDefenderTrojan.Generic.1624522
AgnitumBackdoor.Visel.AGB
Ad-AwareTrojan.Generic.1624522
SophosMal/Generic-S
ComodoBackdoor.Win32.Visel.age
DrWebBackDoor.Darkshell.129
VIPRETrojan.Win32.Generic!BT
AntiVirBDS/Visel.age
McAfee-GW-EditionHeuristic.LooksLike.Win32.Suspicious.C
EmsisoftTrojan.Generic.1624522 (B)
JiangminBackdoor/Visel.ob
KingsoftWin32.Hack.Visel.(kcloud)
MicrosoftBackdoor:Win32/NetThief.gen
AhnLab-V3Trojan/Win32.Black
GDataTrojan.Generic.1624522
CommtouchW32/Backdoor.OMML-0547
PandaGeneric Backdoor
ESET-NOD32a variant of Win32/Nethief.NAM
RisingPE:Trojan.Win32.Generic.136CABD1!325888977
IkarusBackdoor.Win32.Visel
FortinetW32/Malware_fam.NB
AVGBackDoor.Generic11.GVR
Baidu-InternationalTrojan.Win32.Agent.axb

How to remove Backdoor:Win32/NetThief?

Backdoor:Win32/NetThief removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment