Trojan

Trojan.Win32.NetWire.vho malicious file

Malware Removal

The Trojan.Win32.NetWire.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.NetWire.vho virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan.Win32.NetWire.vho?


File Info:

crc32: 0A661E93
md5: 715788fb520b3873db406fdf59521afa
name: 715788FB520B3873DB406FDF59521AFA.mlw
sha1: 096e3741fd8babb84d433fa9ccb866b4fe0435e3
sha256: dbe60153ede523dc838e9289aa0b43c5022c182b85396381b96b5d44c1698e27
sha512: 74a88eba916b6da1dfb3365741df54cdcb7a4faf4029c53c0a39d28753ab674f55230d3aab9af9e4d9b1655adbe08739d9315d8aa9510768aedfebfa4c35c417
ssdeep: 3072:HOzPcXa+ND32eioGHlz8rnAE0HCXh0edLvCYMjMqqDvFf:HOTcK+NrRioGHlz8rz0i/CzQqqDvFf
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.NetWire.vho also known as:

K7AntiVirusSpyware ( 0055216c1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.557
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Netwire
ALYacTrojan.Agent.FCZE
CylanceUnsafe
ZillyaTrojan.Weecnaw.Win32.761
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Weecnaw.a63b22bd
K7GWSpyware ( 0055216c1 )
Cybereasonmalicious.b520b3
CyrenW32/S-6c6572b7!Eldorado
SymantecInfostealer
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.NetWire-8025706-0
KasperskyHEUR:Trojan.Win32.NetWire.vho
BitDefenderTrojan.Agent.FCZE
NANO-AntivirusTrojan.Win32.Wirenet.hlbptg
MicroWorld-eScanTrojan.Agent.FCZE
TencentMalware.Win32.Gencirc.10ce3933
Ad-AwareTrojan.Agent.FCZE
SophosML/PE-A
ComodoMalware@#1eziodjmgtgaq
BitDefenderThetaGen:NN.ZexaF.34790.kCW@amFOnfo
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win32.NETWIRED.SMK
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.715788fb520b3873
EmsisoftTrojan-Spy.Weecnaw (A)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.NetWiredRC.bld
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.309056C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Netwire.PA!MTB
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.FCZE
GDataTrojan.Agent.FCZE
TACHYONTrojan/W32.NetWiredRC.164352
AhnLab-V3Trojan/Win32.RL_NetWiredRC.R342610
McAfeeGenericRXKH-LK!715788FB520B
MAXmalware (ai score=80)
VBA32BScope.TrojanSpy.Loyeetro
MalwarebytesBackdoor.Quasar
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.NETWIRED.SMK
RisingBackdoor.NetWire!1.C98D (CLASSIC)
YandexTrojan.GenAsa!DOgbQEDHp9A
IkarusBackdoor.Rat.Netwire
FortinetW32/Ulise.103681!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NetWire.HxQBdCcA

How to remove Trojan.Win32.NetWire.vho?

Trojan.Win32.NetWire.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment