PUA

Win32:Netscro-B [PUP] removal tips

Malware Removal

The Win32:Netscro-B [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Netscro-B [PUP] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:80
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32:Netscro-B [PUP]?


File Info:

crc32: E21FE3F3
md5: 756e9a919f3263313d2aa615fa2c4e07
name: 756E9A919F3263313D2AA615FA2C4E07.mlw
sha1: ab4587aaeebe307416adf32ca542d4ee61465ca1
sha256: c6f683d875c4d7b463750391aa68524d517400900da8317069de4f7ac6a703b0
sha512: 3a3896b833bdcb084a1a0c0d9777ebb0b7cd34fe6b89ef1c17f37ace011b26e972d4132edc1b48f91abbc3d3892db4616fd788f8434b0ffa921ceb4664bd4881
ssdeep: 24576:w+mXmtLYRKkI4ilAV0nIRbkhnFCZzy0KqiVmy51vGqDp9VLQ8umR49HO:wyUmlg04bkhnFCCqI1+QVZDMu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010 Scuio Corp.
FileVersion: 2, 8, 4128, 0
NetBox Homepage: http://www.scuio.com
ProductVersion: 2, 8, 4128, 0
FileDescription: Powered by Sws
Release DateTime: Sep 04 15:58:57 2010
Translation: 0x0409 0x04b0

Win32:Netscro-B [PUP] also known as:

K7AntiVirusRiskware ( 0040eff71 )
CMCServer-Web.Win32.NetBox!O
CylanceUnsafe
ZillyaAdware.MultiPlug.Win32.498810
SangforMalware
K7GWRiskware ( 0040eff71 )
ESET-NOD32a variant of Win32/Server-Web.NetBox.A potentially unsafe
APEXMalicious
AvastWin32:Netscro-B [PUP]
ClamAVWin.Trojan.Netbox-3
Kasperskynot-a-virus:Server-Web.Win32.NetBox.bey
NANO-AntivirusRiskware.Win32.Server.dkownp
ViRobotTrojan.Win32.S.Agent.1403131
SophosGeneric PUA KL (PUA)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.756e9a919f326331
SentinelOneDFI – Suspicious PE
Endgamemalicious (high confidence)
WebrootW32.Heuristic.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare[Server-Web]/Win32.NetBox
MicrosoftPUA:Win32/Presenoker
JiangminTrojan.Generic.dlehm
AegisLabRiskware.Win32.NetBox.1!c
ZoneAlarmnot-a-virus:Server-Web.Win32.NetBox.bey
AhnLab-V3Trojan/Win32.Netbox.R98811
McAfeeArtemis!756E9A919F32
MAXmalware (ai score=96)
TrendMicro-HouseCallTROJ_GEN.R002H07BI20
YandexRiskware.Server-Web!mSS0vpJb+nE
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32:Netscro-B [PUP]?

Win32:Netscro-B [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment