GridinSoft Threat Intelligence

NETwtw06.sys threat report

Detected as Trojan.Generic File reputation report
MD5 fe1269315d2999724a9bb9a3aa8e6eaf
Latest seen 2024-10-24 23:00:41 (2 years ago)
First seen 2024-10-24 23:00:41 (2 years ago)
Size 8 MB
Publisher Intel Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2024-10-24 23:00:41 (2 years ago)
File hash
fe1269315d2999724a9bb9a3aa8e6eaf
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic, part of the Trojan threat category.

Category context

Malware disguised as legitimate software or delivered through deceptive packaging. Related Trojan reports help compare this file with nearby detections, publishers, and hashes.

Timeline

First seen 2024-10-24 23:00:41 (2 years ago); latest analysis 2024-10-24 23:00:41 (2 years ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present. Review the Trojan category for related samples and common context.

NETwtw06.sys is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Trojan.Generic, based on the latest analysis from 2024-10-24 23:00:41 (2 years ago). ThreatInfo groups this verdict with Trojan reports for broader family-level investigation.

If NETwtw06.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: fe1269315d2999724a9bb9a3aa8e6eaf
Size: 8 MB
First Published: 2024-10-24 23:00:41 (2 years ago)
Latest Published: 2024-10-24 23:00:41 (2 years ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2024-10-24 23:00:41 (2 years ago)
NETwtw06.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%programfiles%\intel\wifidrivers

ThreatInfo has observed NETwtw06.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for NETwtw06.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

NETwtw06.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x0004d740
Image base 0x0000000140000000

PE Sections:

Sections 31
Raw data 8592896

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 4446208 bytes · 51.7% of section data
MD5 a39e19d3d65edf68e0eb373f57502344
.rdata 783872 bytes · 9.1% of section data
MD5 a3356d2235385adce6f59b856ef51411
.data 149504 bytes · 1.7% of section data
MD5 7e28934ab2893b85058316a07bbe66a3
.pdata 202752 bytes · 2.4% of section data
MD5 1365e93a84cee10b939bf2db99e3a52a
PAGEcsrv 87552 bytes · 1.0% of section data
Uncommon name
MD5 d1269e0bda3b1847f201213a23edeecf
PAGEcjaw 95232 bytes · 1.1% of section data
Uncommon name
MD5 3ad152963a8f71cc6a5843aee234265b
PAGE 27648 bytes · 0.3% of section data
Uncommon name
MD5 04a0add76c2c457292b283476f48bca6
PAGEcsec 31232 bytes · 0.4% of section data
Uncommon name
MD5 e1a214025417c6fafd09aac793d7db0b
PAGEcnlo 1536 bytes · 0.0% of section data
Uncommon name
MD5 8b63063694eca0719cc6c4ac67f97cbe
PAGEcwfd 97792 bytes · 1.1% of section data
Uncommon name
MD5 03e1bc60a4591e1e64ca86ceacb29150
PAGEccln 81408 bytes · 0.9% of section data
Uncommon name
MD5 cb1c41825f971b2918113250d67602af
PAGEcsv_ 77824 bytes · 0.9% of section data
Uncommon name
MD5 ba8d2ff6d963d59af7f699626d4cb48a
PAGEcimg 9216 bytes · 0.1% of section data
Uncommon name
MD5 f40e18e8dd7f283c724d3a782f6b76f8
PAGEcpsm 7168 bytes · 0.1% of section data
Uncommon name
MD5 0bb24a8c97c1accbdd5ee47c8cba958d
PAGEcctw 4608 bytes · 0.1% of section data
Uncommon name
MD5 7a61729b17010bebaed196838275bc52
PAGEdoid 28160 bytes · 0.3% of section data
Uncommon name
MD5 725395c96036450cb08a81e322407b00
PAGEdcln 4096 bytes · 0.0% of section data
Uncommon name
MD5 e6c0dd3a273423a1fcff6cda57a10996
PAGEdsv_ 2560 bytes · 0.0% of section data
Uncommon name
MD5 3dad592b368a6baccc7fb0050bea3e3d
PAGEdreg 270848 bytes · 3.2% of section data
Uncommon name
MD5 63478171051626aa1b8acd8ca8cf5a17
PAGEdSnF 512 bytes · 0.0% of section data
Uncommon name
MD5 fb0810974531a17223c64c5371095be8
PAGEdWsP 512 bytes · 0.0% of section data
Uncommon name
MD5 318e70de1108237766e0ff471586ad4e
PAGEdPsr 1024 bytes · 0.0% of section data
Uncommon name
MD5 ef59110a1ebfdb27ec91eb21dec6a31d
PAGEdThP 512 bytes · 0.0% of section data
Uncommon name
MD5 d55f934d4ac58e2d1d2557fb26d7ea1a
PAGEdQua 1024 bytes · 0.0% of section data
Uncommon name
MD5 9f7e50a044b02aae292d18dedbb18b21
PAGEdjaw 1024 bytes · 0.0% of section data
Uncommon name
MD5 efa9ab66cc5c9218c3ac205b7fc76379
PAGEdctw 512 bytes · 0.0% of section data
Uncommon name
MD5 dddcc03e2b592ffd37f7ac3ccb835596
PAGEdimg 2048 bytes · 0.0% of section data
Uncommon name
MD5 1e60d92c044f3f959db9de3891a3ac63
PAGEdrlg 2097152 bytes · 24.4% of section data
Uncommon name
MD5 b2d1236c286a3c0704224fe4105eca49
INIT 5632 bytes · 0.1% of section data
Uncommon name
MD5 4299fd6f4a74c4f3077fdfd3e2538e13
.rsrc 46592 bytes · 0.5% of section data
MD5 02b18c6b40fa16d6f4cc7f56ce655e0e
.reloc 27136 bytes · 0.3% of section data
MD5 94a995c7175d62a70c3da5eb6845eb53

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Generic

This report identifies NETwtw06.sys by MD5 fe1269315d2999724a9bb9a3aa8e6eaf. It is part of the Trojan report group. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with fe1269315d2999724a9bb9a3aa8e6eaf.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found. Use the Trojan category to compare similar reports.