Netwtw08.sys threat report

MD5 d6d977726043ebe09259f282b8f95ca1
Latest seen 2024-10-03 23:04:59 (2 years ago)
First seen 2024-10-03 23:04:59 (2 years ago)
Size 8 MB
Publisher Intel Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2024-10-03 23:04:59 (2 years ago)
File hash
d6d977726043ebe09259f282b8f95ca1
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2024-10-03 23:04:59 (2 years ago); latest analysis 2024-10-03 23:04:59 (2 years ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

Netwtw08.sys is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Trojan.Generic, based on the latest analysis from 2024-10-03 23:04:59 (2 years ago).

If Netwtw08.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: d6d977726043ebe09259f282b8f95ca1
Size: 8 MB
First Published: 2024-10-03 23:04:59 (2 years ago)
Latest Published: 2024-10-03 23:04:59 (2 years ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2024-10-03 23:04:59 (2 years ago)
Netwtw08.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%system%\driverstore\filerepository

ThreatInfo has observed Netwtw08.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Germany with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for Netwtw08.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Netwtw08.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000585d0

PE Sections:

Name Size of data MD5
.text 4741120 4ea4272ad844c1ab034a14a39f62c66a
.rdata 758784 370c5a321817402453459da2fa362553
.data 321024 a7b4cbf804ee66c81f80bf30565be731
.pdata 205312 513f5b065eefcf72183ed20461fa955c
PAGEcsrv 69120 8c46289d23e72f9cb727ba979e14f2fc
PAGEcjaw 79360 ac0116f6b99fc77c666d78d178bfa881
PAGEcsec 512 38287f94abd46c43ee14f38369b13aee
PAGE 4608 bee86a7631cd56bb810e5539f7059c49
PAGEcwfd 99840 137226f67fc893001f5f319b2cb0b65d
PAGEccln 87040 b9eef3bb8cc0a9d0eaf26a53a1242149
PAGEcsv_ 42496 1a4924bfe7c96b921cd546d81f9a6df6
PAGEcimg 11776 19f86140960769996db90b11324d0a86
PAGEcctw 512 f25161b91670af4d6f34c6a736e9bd6c
PAGEdoid 12800 ed3e71b8a97fbda4d78ba93b00b6dea1
PAGEdcln 4608 2d8db9ceb84ffa18ad3470aeffa731dd
PAGEdsv_ 4608 0121a761f8898bc0b19231b479af5349
PAGEdreg 260608 1e3b3514463c02656aed28c2b442e22c
PAGEdSnF 512 2c2fd4f4cc2fdc59e5a9dadf3fceb4a3
PAGEdWsP 512 0d4f74ee8c266835a4a522eae1c66ef5
PAGEdPsr 1536 d3d82c304de0aff2ffbfa81cc33d7ccc
PAGEdThP 512 b8e9a44c058aa04ab482cedc8f32447e
PAGEdQua 1536 7b3199e63345f8033064f4d073a50768
PAGEdSun 1536 c1fbd84520b0d836ac66eebd9e77ccf0
PAGEdSlr 1536 c1fbd84520b0d836ac66eebd9e77ccf0
PAGEdCcl 1024 e41b72379d703f718a0cc5299d249fb0
PAGEdSim 512 4588a81226c2f4931d4d659fe0760706
PAGEdFpg 512 15bc713943f81bff1eae5dfdbbb87f1f
PAGEdSle 512 40fef1709b7383441032e2631e0ba48d
PAGEdjaw 1024 f62f4759707c56b6217ac6317d6fa0cc
PAGEdimg 512 81cf98f8e867b35cc557959a1bb31bf1
PAGEdrlg 2097152 b2d1236c286a3c0704224fe4105eca49
INIT 5632 f107fc96e0c4996af197914c203168bd
.rsrc 47104 09eb765b1f97ff98559c92442b4895f8
.reloc 46080 1649192da1a58832fe1bc13fe5e64c73

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: