Backdoor

Backdoor:Win32/NetWiredRC.C removal

Malware Removal

The Backdoor:Win32/NetWiredRC.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/NetWiredRC.C virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Creates a hidden or system file

Related domains:

onyeoma50505.chickenkiller.com
onyeoma5050s.ddns.net

How to determine Backdoor:Win32/NetWiredRC.C?


File Info:

crc32: 81AAE4CA
md5: 20a92afb4c6b67ac138a1891ddb07606
name: Swift USD45,850.zip
sha1: 28870f0faac64d60404ec57e3442201c45ce4e41
sha256: b4bff2f381a3870ba917525f2ab95047e26cf6e6ab69dd783d25f55209bf6608
sha512: 2fca69ba8c0be41b77e4224cecf39635234a0681193a0d23397602699ed2f70cff9d47625bd3ec06bc28d95c132b39cf9ab71061d5ee2fa3ec87c51e70a3245c
ssdeep: 12288:zGZzNNwM/8TXY9H6pKsOus5YrULYcwdThCQsxBzXHF8KRNQpHGlQVDsQn:zKzjHEGPI2J2CHzXHxKHGlesQn
type: Zip archive data, at least v2.0 to extract

Version Info:

0: [No Data]

Backdoor:Win32/NetWiredRC.C also known as:

MicroWorld-eScanTrojan.Generic.17881461
McAfeeArtemis!AF53BE81004B
K7AntiVirusTrojan ( 004f54811 )
BitDefenderTrojan.Generic.17881461
K7GWTrojan ( 004f54811 )
BaiduWin32.Trojan.Autoit.cb
TrendMicro-HouseCallTROJ_UTOTI.SMDA
AvastAutoIt:Agent-ANS [Trj]
ClamAVWin.Malware.Autoit-6987423-0
KasperskyTrojan-Spy.Win32.Recam.abcg
AlibabaTrojanSpy:Win32/Recam.ee95bca2
NANO-AntivirusTrojan.Script.AutoItAgent.ejermi
AegisLabTrojan.Win32.Recam.l!c
RisingTrojan.Injector!8.C4 (TOPIS:E0:F6ozsjLFWGF)
Endgamemalicious (high confidence)
EmsisoftTrojan.Generic.17881461 (B)
F-SecureDropper.DR/Autoit.inbi
DrWebTrojan.Inject2.27722
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_UTOTI.SMDA
McAfee-GW-EditionBehavesLike.Ransomware.jc
FortinetW32/Agent.YMG!tr
FireEyeTrojan.Generic.17881461
SophosTroj/Inject-CAN
IkarusTrojan.Autoit
AviraSwift
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D110D975
ZoneAlarmTrojan-Spy.Win32.Recam.abcg
MicrosoftBackdoor:Win32/NetWiredRC.C
ALYacTrojan.Generic.17881461
ESET-NOD32a variant of Win32/Packed.CAB.I
TencentWin32.Trojan-spy.Recam.Hpsb
SentinelOneDFI – Suspicious Archive
GDataScript.Trojan-Downloader.Rednib.A
AVGAutoIt:Agent-ANS [Trj]
PandaTrj/CI.A

How to remove Backdoor:Win32/NetWiredRC.C?

Backdoor:Win32/NetWiredRC.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment