Backdoor

Backdoor:Win32/Netwire.PA!MTB removal guide

Malware Removal

The Backdoor:Win32/Netwire.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Netwire.PA!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Netwire.PA!MTB?


File Info:

crc32: 1F94ED37
md5: 60d234d54c25dcef19a64ded3a587072
name: 60D234D54C25DCEF19A64DED3A587072.mlw
sha1: 7209018f3e29225363f92f7e04e35ca7001dcf39
sha256: 4f10d7a2e964aa6c91e4b2da80fe82f8a566ca8a541592a4789b48f4dba11581
sha512: a67d5a511809d0bbff7d8a327fc63e47713bb0928488028441f41dbbc75c5b759607af437b7617446e730debabc427aaf5f1b945c715e3e454d17811be921674
ssdeep: 3072:jOzPcXa+ND32eioGHlz8rnAE0HCXh0edLvCYMjMqqDvFf:jOTcK+NrRioGHlz8rz0i/CzQqqDvFf
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Netwire.PA!MTB also known as:

K7AntiVirusSpyware ( 0055216c1 )
LionicTrojan.Win32.NetWire.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.557
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.NetWiredRC
ALYacTrojan.Agent.FCZE
CylanceUnsafe
ZillyaTrojan.Weecnaw.Win32.761
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/NetWiredRC.837da9e3
K7GWSpyware ( 0055216c1 )
Cybereasonmalicious.54c25d
CyrenW32/S-6c6572b7!Eldorado
SymantecInfostealer
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.NetWire-8025706-0
KasperskyBackdoor.Win32.NetWiredRC.lac
BitDefenderTrojan.Agent.FCZE
NANO-AntivirusTrojan.Win32.Wirenet.hlbptg
MicroWorld-eScanTrojan.Agent.FCZE
TencentMalware.Win32.Gencirc.10ce3933
Ad-AwareTrojan.Agent.FCZE
SophosMal/Generic-S
ComodoMalware@#3ioulbaqsgkod
BitDefenderThetaGen:NN.ZexaF.34790.kCW@amsq2rh
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win32.NETWIRED.SMK
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.60d234d54c25dcef
EmsisoftTrojan.Agent.FCZE (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.NetWiredRC.bld
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.309056C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Netwire.PA!MTB
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.FCZE
ZoneAlarmBackdoor.Win32.NetWiredRC.lac
GDataTrojan.Agent.FCZE
TACHYONTrojan/W32.NetWiredRC.164352
AhnLab-V3Trojan/Win32.RL_NetWiredRC.R342610
McAfeeGenericRXKH-LK!60D234D54C25
MAXmalware (ai score=87)
VBA32BScope.TrojanSpy.Loyeetro
MalwarebytesBackdoor.Quasar
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.NETWIRED.SMK
RisingBackdoor.NetWire!1.C98D (CLASSIC)
YandexTrojan.GenAsa!DOgbQEDHp9A
IkarusBackdoor.Rat.Netwire
MaxSecureTrojan.Malware.102170081.susgen
FortinetW32/Ulise.103681!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NetWire.HxQBcLcA

How to remove Backdoor:Win32/Netwire.PA!MTB?

Backdoor:Win32/Netwire.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment