Malware

Should I remove “Win32:Netwire-A [Trj]”?

Malware Removal

The Win32:Netwire-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Netwire-A [Trj] virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Detects NetWire Behavior
  • CAPE detected the NetWire malware family
  • Creates a copy of itself

How to determine Win32:Netwire-A [Trj]?


File Info:

name: 831291F319B73DB9F96E.mlw
path: /opt/CAPEv2/storage/binaries/8e5c76a2830bd4e43f3331e82c646219efdcce18e11cc0501bd1a85201985dc5
crc32: 6E875369
md5: 831291f319b73db9f96e5e9cfe90bb05
sha1: dcba53d065e0259723cf57b95d233b6ca9bd67ed
sha256: 8e5c76a2830bd4e43f3331e82c646219efdcce18e11cc0501bd1a85201985dc5
sha512: 4aef9675d75b51306faad47b6c9b016cdbf4149efd1b5a9876d01875aefba675ba0c5655430b78b03ea34cbbbf05d20d1ea80816931f9167c4f59ab93faa1ba3
ssdeep: 1536:6IhBcw12qrzrVuQz5g1YSmicguYevhBWuxvRtJj7Oq:BtLn5gLcFYehr3Oq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D5302C4D04B197AFE7306FB14D257B4BA249965D3ACDF81197D02F5BD6206CBC8860D
sha3_384: ea9dbbb1a0d10e614578f54d31287cdfc06e2290f17f86d266995335ce30d9bf8be726a0d78c6aa7515bc2963b307646
ep_bytes: 60be15f041008dbeeb1ffeff5783cdff
timestamp: 2019-10-30 08:25:44

Version Info:

0: [No Data]

Win32:Netwire-A [Trj] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Malware.NetWire-8792201-1
FireEyeGeneric.mg.831291f319b73db9
CAT-QuickHealTrojan.NetwirePMF.S19647199
McAfeeGenericRXAA-AA!831291F319B7
CylanceUnsafe
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/NetWire.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Heur.Variadic.A.187.1
NANO-AntivirusTrojan.Win32.NetWire.gisnhf
MicroWorld-eScanGen:Heur.Variadic.A.187.1
AvastWin32:Netwire-A [Trj]
TencentMalware.Win32.Gencirc.10ce83fa
Ad-AwareGen:Heur.Variadic.A.187.1
SophosTroj/Agent-BFAR
ComodoTrojWare.Win32.Spy.Weecnaw.FDA@8syc9v
DrWebBackDoor.Wirenet.540
TrendMicroBackdoor.Win32.NETWIRED.SMK
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
EmsisoftGen:Heur.Variadic.A.187.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Variadic.A.187.1
JiangminTrojan.NetWire.mn
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30CAC5C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Backdoor/Win.NETWIRED.R433389
BitDefenderThetaGen:NN.ZexaF.34062.dmGfaicu0fk
ALYacGen:Heur.Variadic.A.187.1
MAXmalware (ai score=81)
VBA32BScope.Backdoor.NetWiredRC
TrendMicro-HouseCallBackdoor.Win32.NETWIRED.SMK
RisingBackdoor.NetWire!1.B84F (CLASSIC)
YandexTrojan.GenAsa!vz6FqGtuWOE
IkarusTrojan.Win32.Claretore
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/NetWired.SMK!tr
AVGWin32:Netwire-A [Trj]
Cybereasonmalicious.319b73
PandaTrj/Genetic.gen

How to remove Win32:Netwire-A [Trj]?

Win32:Netwire-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment