Trojan

What is “Trojan.Win32.NetWire.ikf”?

Malware Removal

The Trojan.Win32.NetWire.ikf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.NetWire.ikf virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

Related domains:

leshdksvc.ug
vcdjhbgerwgdfkn.ru

How to determine Trojan.Win32.NetWire.ikf?


File Info:

crc32: CC064CA6
md5: fa8ade1eee542bb4c9cdf5d04c13c8b8
name: nfdvcxtghs.exe
sha1: da485d7ebad39d57328f70d179fc105ac968c053
sha256: be39b6e20c5f99540a5fc3ca5c884eea172fef986587ab6cdca1672c87503eaa
sha512: 61fd2b95c7d98bef4a1cf4a042f917d53da1c1684db5b26dc80cdd129e467d99324edfd38a510a02fd46e948817074f3f006c16b40de6221f4b4a1cbc357cf1d
ssdeep: 6144:s/ksN2f1wvBGrIcvVyXWcVtegOTNBoLNzP:s/knNwvBGscvuWAtegOwB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Plantagenet 2019
InternalName: copastors.exe
FileVersion: 1.4.8.6
CompanyName: conch
ProductName: taramasalata
ProductVersion: 0.8.2.5
FileDescription: nonadaptor
OriginalFilename: LWSP.exe
Translation: 0x0409 0x04b0

Trojan.Win32.NetWire.ikf also known as:

MicroWorld-eScanGen:Variant.Ulise.96875
FireEyeGeneric.mg.fa8ade1eee542bb4
McAfeeRDN/Generic.grp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055f5801 )
BitDefenderGen:Variant.Ulise.96875
K7GWTrojan ( 0055f5801 )
CrowdStrikewin/malicious_confidence_100% (W)
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Ulise.96875
KasperskyTrojan.Win32.NetWire.ikf
AlibabaTrojan:Win32/GenKryptik.1df2bbcb
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.96875 (B)
F-SecureTrojan.TR/Kryptik.bcqdg
DrWebTrojan.Encoder.29362
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.QWOV-1020
JiangminTrojan.PSW.MSIL.lse
WebrootW32.Trojan.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ulise.D17A6B
ZoneAlarmTrojan.Win32.NetWire.ikf
BitDefenderThetaGen:NN.ZexaF.34084.rC3@aC0QDEpi
ALYacGen:Variant.Ulise.96875
VBA32BScope.Trojan.Meterpreter
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.ECRE
TencentWin32.Trojan.Ulise.Efaw
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_60%
FortinetW32/Generic.AP.20ADFE6!tr
Ad-AwareGen:Variant.Ulise.96875
AVGWin32:Trojan-gen
Cybereasonmalicious.ebad39
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM10.2.D507.Malware.Gen

How to remove Trojan.Win32.NetWire.ikf?

Trojan.Win32.NetWire.ikf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment