Trojan

Trojan:Win32/NetWire.YL removal guide

Malware Removal

The Trojan:Win32/NetWire.YL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/NetWire.YL virus can do?

  • A process attempted to delay the analysis task.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fousteri.giize.com
houstedm.kozow.com
houstrikqs.freeddns.org
hojkstril.loseyourip.com

How to determine Trojan:Win32/NetWire.YL?


File Info:

crc32: 2D3526BD
md5: a19fae54d919c371d7d30c9244264dce
name: 7.exe
sha1: fb80c7190f9ffffaf0b222da9b95b19deac5213d
sha256: d1a8290523eddf2159a0f0d2ec5cff9e90646f11cd6bdade0a0c29b05aab2145
sha512: 00dc0ae797eba09cb07661ce925a228d5edb162864e2f77fe43beba8590fad1503802ef1384ab8516f34f5cb030e4b7712a3ebfe5792b781b241065a11ecdb0c
ssdeep: 3072:ROzIy5XGViztldWl88Yed2DQuIAQvQ+d0aY5RX:Ro2ViztvWlvd2UuIAQvQ+yF5R
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/NetWire.YL also known as:

MicroWorld-eScanGen:Heur.IPZ.7
FireEyeGeneric.mg.a19fae54d919c371
CAT-QuickHealTrojan.Generic
McAfeeGenericRXHY-GQ!A19FAE54D919
MalwarebytesBackdoor.NetWiredRC
ZillyaTrojan.Generic.Win32.896925
K7AntiVirusSpyware ( 0055216c1 )
BitDefenderGen:Heur.IPZ.7
K7GWSpyware ( 0055216c1 )
Cybereasonmalicious.4d919c
TrendMicroBackdoor.Win32.NETWIRED.SMK
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Malware.Razy-6703914-0
GDataWin32.Backdoor.NetWireRC.2Y1J21
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Weecnaw.ftaqim
RisingBackdoor.Agent!1.B84F (CLASSIC)
Ad-AwareGen:Heur.IPZ.7
SophosTroj/Netwire-MS
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.MulDrop9.35491
McAfee-GW-EditionBehavesLike.Win32.PWSOnlineGames.ch
EmsisoftGen:Heur.IPZ.7 (B)
IkarusTrojan-Spy.Agent
JiangminTrojan.Generic.dmisn
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.IPZ.7
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/NetWire.YL
AhnLab-V3Trojan/Win32.NetWiredRC.R287756
Acronissuspicious
VBA32BScope.TrojanSpy.Loyeetro
ALYacGen:Heur.IPZ.7
MAXmalware (ai score=84)
CylanceUnsafe
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
TrendMicro-HouseCallBackdoor.Win32.NETWIRED.SMK
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_64%
FortinetW32/Weecnaw.P!tr.spy
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM20.1.E293.Malware.Gen

How to remove Trojan:Win32/NetWire.YL?

Trojan:Win32/NetWire.YL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment