Home Malware Programs Backdoors Backdoor.NetWiredRC.A

Backdoor.NetWiredRC.A

Posted: May 15, 2013

Threat Metric

Ranking: 16,319
Threat Level: 6/10
Infected PCs: 1,995
First Seen: May 15, 2013
Last Seen: March 1, 2025
OS(es) Affected: Windows

Aliases

Trj/CI.A [Panda]BackDoor.Generic16.ESN [AVG]MSIL/Injector.QR!tr [Fortinet]Backdoor.Win32.DarkKomet [Ikarus]Trojan/Win32.Blocker [AhnLab-V3]Backdoor:Win32/NetWiredRC.A [Microsoft]TR/Dropper.MSIL.Gen8 [AntiVir]BackDoor.Siggen.48301 [DrWeb]UnclassifiedMalware [Comodo]Trojan-Ransom.Win32.Blocker.abhe [Kaspersky]MSIL:Agent-WB [Trj] [Avast]Artemis!4D6188FBE2F9 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Downloads\das_malwerk\b4d73b07aa627674b03f9c96dd5883dcd78b73e5baba6426dcc87ff0e771b265\b4d73b07aa627674b03f9c96dd5883dcd78b73e5baba6426dcc87ff0e771b265.exe File name: b4d73b07aa627674b03f9c96dd5883dcd78b73e5baba6426dcc87ff0e771b265.exe
Size: 467.03 KB (467032 bytes)
MD5: 0c725cb728834cf1a3cc041f09d1975a
Detection count: 311
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\das_malwerk\b4d73b07aa627674b03f9c96dd5883dcd78b73e5baba6426dcc87ff0e771b265\b4d73b07aa627674b03f9c96dd5883dcd78b73e5baba6426dcc87ff0e771b265.exe
Group: Malware file
Last Updated: November 10, 2023
file.exe File name: file.exe
Size: 622.13 KB (622136 bytes)
MD5: 90f84873b046afc33c4894ab6758f66c
Detection count: 8
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%APPDATA%\FacbookUpdate.exe File name: FacbookUpdate.exe
Size: 771.07 KB (771072 bytes)
MD5: 4d6188fbe2f9ba21429b304b82a1ecc3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2013
%APPDATA%\Microsoft\eacbucva\utsshvdc.exe File name: utsshvdc.exe
Size: 395.77 KB (395776 bytes)
MD5: 80f2fca1418d43543b454fc1846ae5ef
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\eacbucva
Group: Malware file
Last Updated: August 10, 2017
c:\Users\<username>\desktop\d61d0b7e524f4b94016c765a87212a7e201566af2c431f2c7369f85f07e79bae.exe File name: d61d0b7e524f4b94016c765a87212a7e201566af2c431f2c7369f85f07e79bae.exe
Size: 531.45 KB (531456 bytes)
MD5: 64af70010d99fd16e643408465604d22
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\desktop
Group: Malware file
Last Updated: March 23, 2018

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Install\mswords.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Winhost.url%TEMP%\Host.exe

Additional Information

The following directories were created:
%APPDATA%\mscftmon
Loading...