Netwtw08.sys threat report

MD5 279eeb0f549cb696e799c594ac469152
Latest seen 2025-01-25 23:05:21 (a year ago)
First seen 2025-01-25 23:05:18 (a year ago)
Size 8 MB
Publisher Intel Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2025-01-25 23:05:21 (a year ago)
File hash
279eeb0f549cb696e799c594ac469152
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2025-01-25 23:05:18 (a year ago); latest analysis 2025-01-25 23:05:21 (a year ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

Netwtw08.sys is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Trojan.Generic, based on the latest analysis from 2025-01-25 23:05:21 (a year ago).

If Netwtw08.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: 279eeb0f549cb696e799c594ac469152
Size: 8 MB
First Published: 2025-01-25 23:05:18 (a year ago)
Latest Published: 2025-01-25 23:05:21 (a year ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2025-01-25 23:05:21 (a year ago)
Netwtw08.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%system%\driverstore\filerepository
%system%\driverstore\filerepository

ThreatInfo has observed Netwtw08.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Iraq with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for Netwtw08.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Netwtw08.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000585d0

PE Sections:

Name Size of data MD5
.text 4743680 e57f1fc1493459b484df7c46980ee39b
.rdata 759296 b8692f551c82fc992ce6f54caea1d564
.data 321024 579f03dfb830aa9c17f1849df3da9f97
.pdata 205312 a044d8a44da2dc9053990a69aabd184b
PAGEcsrv 69120 083fa5bf4e950e8136c8cf2fc8f6ea7d
PAGEcjaw 79360 ad3dc60b7e3608144122a5c111840bbc
PAGEcsec 512 38287f94abd46c43ee14f38369b13aee
PAGE 4608 afaf57570e728e78111a03adf5d57658
PAGEcwfd 99840 849cec6db712467ced81cd680eb207a4
PAGEccln 87040 c3432a2cf6e41b3260504bac8ef1f2c5
PAGEcsv_ 42496 fea2e2ee257294fbd01ad8df88b43332
PAGEcimg 11776 a2a5382107e4d4150d56115bb918beba
PAGEcctw 512 20e4cb0d1ac69e4c226084fd5e6eac12
PAGEdoid 12800 439c46479f3560aed3e24c9f5ef5291a
PAGEdcln 4608 2b44d4fe4cccfaf84798ddb6c892483f
PAGEdsv_ 4608 0121a761f8898bc0b19231b479af5349
PAGEdreg 261120 f1ad6fb0e2771049bf9102e9e716f6da
PAGEdSnF 512 bb3c1875ffbd2ff6c8571f4cf1d3f3d8
PAGEdWsP 512 a1b59c8cf5e687ef3fef761e0016df22
PAGEdPsr 1536 b19605a8ce4a57faf1583dfb048f93a8
PAGEdThP 512 b8e9a44c058aa04ab482cedc8f32447e
PAGEdQua 1536 d5bafb3b5cc8bb5dc49c52c5988a7600
PAGEdSun 1536 e3e7728c473c57ba22f782117d7f2026
PAGEdSlr 1536 e3e7728c473c57ba22f782117d7f2026
PAGEdCcl 1024 4d1ce2e1283992b986adc9b788759cd2
PAGEdSim 512 4588a81226c2f4931d4d659fe0760706
PAGEdFpg 512 15bc713943f81bff1eae5dfdbbb87f1f
PAGEdSle 512 40fef1709b7383441032e2631e0ba48d
PAGEdjaw 1024 f9d0603feff2b4d99dbd976cb32c2cb3
PAGEdimg 512 c330e76dd67d198152f8b58046f3f3a0
PAGEdrlg 2097152 b2d1236c286a3c0704224fe4105eca49
INIT 5632 b547cb1bb9e9cd0033b039b21088bde7
.rsrc 47104 73d0c83c6d0f539358671e544d75d88f
.reloc 46080 3b1baca0e9f2c0fb0b47b1c4fd8a65f8

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: