Backdoor

About “Backdoor:Win32/NetWiredRC.AB!bit” infection

Malware Removal

The Backdoor:Win32/NetWiredRC.AB!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/NetWiredRC.AB!bit virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Backdoor:Win32/NetWiredRC.AB!bit?


File Info:

crc32: F78AA42C
md5: 48944a7136fd233d222f58e8c33bf60c
name: dwmw.exe
sha1: 53bf681268460c0ab9557ed5dc4d244bf3dee883
sha256: d54debe5902b9af2050c43b8fc52e8a451609e0beefa36877fb072873520400a
sha512: 0800968e6876fefabd47da5a7f0ce8b748e566b31f495ec4431da05949331b22e740263d3e2a455fad7e42531707f863c43eb9c8f648f98ca1aca951cde8a74c
ssdeep: 12288:m9i/+oHdI5UimoJzAsCBfctzcw9eW/aNatPE+kdoMWGeYl5:m92oJzRCBUtN9iiadIGFl5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ASUSTek Computer Inc.
InternalName: ASUS Virtual Camera Setting Applicaion
FileVersion: 1, 0, 27, 0
CompanyName: ASUSTek Computer Inc.
ProductName: ASUS Virtual Camera
ProductVersion: 1, 0, 27, 0
FileDescription: ASUS Virtual Camera Setting Applicaion
OriginalFilename: VirCam.exe
Translation: 0x0804 0x04b0

Backdoor:Win32/NetWiredRC.AB!bit also known as:

MicroWorld-eScanTrojan.GenericKD.5251398
FireEyeGeneric.mg.48944a7136fd233d
Qihoo-360Win32/Trojan.Spy.af7
McAfeeArtemis!48944A7136FD
CylanceUnsafe
ZillyaTrojan.Recam.Win32.1968
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.5251398
K7GWTrojan ( 0050ecaa1 )
K7AntiVirusTrojan ( 0050ecaa1 )
SymantecTrojan Horse
APEXMalicious
GDataTrojan.GenericKD.5251398
KasperskyTrojan-Spy.Win32.Recam.aesc
AlibabaTrojanSpy:Win32/Recam.e76badc8
NANO-AntivirusTrojan.Win32.Recam.euueax
AegisLabTrojan.Multi.Generic.4!c
RisingSpyware.Recam!8.5E5 (TFE:5:Q1a6LDmN8pC)
EmsisoftTrojan.GenericKD.5251398 (B)
ComodoMalware@#15uzx3lq5pgxs
F-SecureTrojan.TR/Recam.ipygj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DLU19
McAfee-GW-EditionArtemis!Trojan
SophosTroj/Recam-CY
IkarusTrojan-Spy.Win32.Recam
JiangminTrojanSpy.Recam.bib
WebrootW32.Trojan.GenKD
AviraTR/Recam.ipygj
MicrosoftBackdoor:Win32/NetWiredRC.AB!bit
ArcabitTrojan.Generic.D502146
ZoneAlarmTrojan-Spy.Win32.Recam.aesc
AhnLab-V3Malware/Gen.Generic.C1975772
VBA32BScope.TrojanSpy.Recam
ALYacTrojan.GenericKD.5251398
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.5251398
PandaTrj/CI.A
ESET-NOD32a variant of Generik.KWSUOBU
TrendMicro-HouseCallTROJ_GEN.R002C0DLU19
TencentWin32.Trojan-spy.Recam.Pega
eGambitPE.Heur.InvalidSig
FortinetW32/Recam.AESC!tr
BitDefenderThetaGen:NN.ZexaF.34098.0q2@aeQaNilj
AVGFileRepMalware
Cybereasonmalicious.136fd2
Paloaltogeneric.ml
MaxSecureTrojan.Malware.1728101.susgen

How to remove Backdoor:Win32/NetWiredRC.AB!bit?

Backdoor:Win32/NetWiredRC.AB!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment