Trojan

Trojan.Win32.NetWire.hqe removal instruction

Malware Removal

The Trojan.Win32.NetWire.hqe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.NetWire.hqe virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.NetWire.hqe?


File Info:

crc32: 09D8EC16
md5: 3eda556c9a7a05b31acea3d03a71000c
name: vnclife.exe
sha1: f3995027a4baae9cf14dbd701edaa153f0586d35
sha256: 951149380f6ed895d2666318ef8c91f2481f1e133130cf09ccee9dfcb0c49f9b
sha512: e80564e875950e2ae36a7a0a8f6f3bf9fb1fef9b5e256417f2f4b810e64ec55fcc2fe103786b444cf4e2747e0bc2c26020a6ecf20d34e28ea468b1f6015da9e3
ssdeep: 12288:DP3AloP76knmuH5H29yHx2k3EAGFXPl1YfUv1tbKNMqPI/no76+3W40VWq:DP9/nmq5H2kJ3Elnnyiv/noe+3riWq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 1
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Try Your Luck
ProductVersion: 1.00
OriginalFilename: 1.exe

Trojan.Win32.NetWire.hqe also known as:

MicroWorld-eScanTrojan.GenericKD.32766614
McAfeeArtemis!3EDA556C9A7A
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0053b3c61 )
BitDefenderTrojan.GenericKD.32766614
K7GWTrojan ( 0053b3c61 )
TrendMicroTROJ_GEN.R004C0RL119
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.DZRT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.NetWire.hqe
AlibabaTrojan:Win32/Injector.ef8b0111
NANO-AntivirusTrojan.Win32.Dwn.gkbizc
ViRobotTrojan.Win32.Z.Wacatac.1241088.G
Ad-AwareTrojan.GenericKD.32766614
EmsisoftTrojan.GenericKD.32766614 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader30.45983
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Swisyn.th
FortinetW32/DZRT.U!tr
FireEyeGeneric.mg.3eda556c9a7a05b3
SophosMal/FakeMS-U
SentinelOneDFI – Malicious PE
CyrenW32/VBInject.AAG.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=94)
Antiy-AVLTrojan/Win32.NetWire
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F3FA96
ZoneAlarmTrojan.Win32.NetWire.hqe
MicrosoftTrojan:Win32/Tiggre!plock
AhnLab-V3Trojan/Win32.Injector.C3609780
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.32766614
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R004C0RL119
IkarusBackdoor.Win32.Ruskill
eGambitUnsafe.AI_Score_69%
GDataTrojan.GenericKD.32766614
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.bfc

How to remove Trojan.Win32.NetWire.hqe?

Trojan.Win32.NetWire.hqe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment