Trojan

About “Trojan:Win32/Netwire.SD!MTB” infection

Malware Removal

The Trojan:Win32/Netwire.SD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Netwire.SD!MTB virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Netwire.SD!MTB?


File Info:

crc32: 0E9625A8
md5: fd2f40ff15b7a6879bed1a725810bfb8
name: 6433944015527441691586597335467506.exe
sha1: 648b6d832334d774eac07fb7ecd90854dc10214d
sha256: de387fcd42d4c983c771c50bec4af09a6bdf8daf9a798b540c02f7d3cb7360e1
sha512: c95edbae8bbd448daa45001315d50da948dfcf74768ae9cd7d0c5db75e8ecaf6ea4e5d55907e2f7a747d8d7d4a0ab02028adcc8f154d92c99d89b4e9cd5b6ad3
ssdeep: 12288:Oj8r4D4eHvq8DNR4vN08Vav9+k39szD3iU4YcKImo9WY80pHqLARg0NGb2XlGI1:T4D4ePHRwav9uP3MYE80pHqLAuQtlN1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Tim Kosse
FileVersion: 3.47.1
CompanyName: Tim Kosse
ProductName: FileZilla
ProductVersion: 3.47.1
FileDescription: FileZilla FTP Client
OriginalFilename: FileZilla_3.47.1_win32-setup.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Netwire.SD!MTB also known as:

MicroWorld-eScanGen:Variant.Barys.52456
FireEyeGeneric.mg.fd2f40ff15b7a687
McAfeeArtemis!FD2F40FF15B7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056349f1 )
BitDefenderGen:Variant.Barys.52456
K7GWTrojan ( 0056349f1 )
Cybereasonmalicious.f15b7a
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34104.Wm2@ayixe7ni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.VFM
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Barys.52456
KasperskyHEUR:Trojan.MSIL.Injects.gen
AegisLabTrojan.Win32.Barys.4!c
TencentWin32.Trojan.Falsesign.Edxn
Ad-AwareGen:Variant.Barys.52456
EmsisoftGen:Variant.Barys.52456 (B)
F-SecureHeuristic.HEUR/AGEN.1034514
DrWebTrojan.DownLoader33.20996
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
CyrenW32/Trojan.DIRL-5678
eGambitPE.Heur.InvalidSig
AviraHEUR/AGEN.1034514
MAXmalware (ai score=99)
Antiy-AVLTrojan/MSIL.Injects
Endgamemalicious (high confidence)
ArcabitTrojan.Barys.DCCE8
ZoneAlarmHEUR:Trojan.MSIL.Injects.gen
MicrosoftTrojan:Win32/Netwire.SD!MTB
Acronissuspicious
ALYacGen:Variant.Barys.52456
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H09CO20
RisingTrojan.Netwire!8.FAFE (CLOUD)
SentinelOneDFI – Malicious PE
FortinetMSIL/Kryptik.VDT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.de5

How to remove Trojan:Win32/Netwire.SD!MTB?

Trojan:Win32/Netwire.SD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment