Systweak Spyware Library
Systweak Spyware Library text
More than 1309737 spyware signatures and growing
Microsoft Gold Certified Partner
Search in:
Trojan.agent.nas Analysis Report
Threat Submitted On: 6/8/2008 4:07:04 PM
Threat Analysed On: 6/8/2008 9:07:04 PM
Threat Updated On: 11/9/2009 3:23:05 PM
Type : Trojan
Symptoms of agent.nas
  • Performs illicit activities under the disguise of a useful program.
  • Download malicious code and programs such as keyloggers.
  • It is capable of fetching user’s personal and confidential information.
Information
Alias : trojan.win32.agent.nas
Md5 Hash : [060cd5d5a7a187cd069fb168a26654bf]
File Size : (3755528 bytes)

Here are the Technical findings of our analysis team after analyzing this malware in detail :-

Creates the following infected Files on user's System
Note:
Delete the following Files to remove Infection
File: netpumper help.lnk
Path : %allusersprofile%\start menu\programs\netpumper

Md5Hash :d1b95e89668932e13108d5ec4cb2f1d1 ( 790 bytes)
File: netpumper.lnk
Path : %allusersprofile%\start menu\programs\netpumper

Md5Hash :5f7821de0eea5387f9ada516ba202154 ( 1633 bytes)
File: readme.lnk
Path : %allusersprofile%\start menu\programs\netpumper

Md5Hash :7678ef4c62d721fef9436ed13086e69e ( 730 bytes)
File: shutdown netpumper.lnk
Path : %allusersprofile%\start menu\programs\netpumper

Md5Hash :a4bdf97702f8b56c7c983da76e00cfef ( 742 bytes)
File: uninstall netpumper.lnk
Path : %allusersprofile%\start menu\programs\netpumper

Md5Hash :d077c955f8544b5c9ee04f1216a66831 ( 688 bytes)
File: addurl.htm
Path : %programfiles%\netpumper

Md5Hash :682f40892232577b48f06f5a9ddb97c9 ( 819 bytes)
File: compat.htm
Path : %programfiles%\netpumper\help

Md5Hash :0b0bd4df133981c2dbb7ed6d33e150dd ( 9286 bytes)
File: details.htm
Path : %programfiles%\netpumper\help

Md5Hash :4f71c26f9b43d7e85a1bcddfeb49ee28 ( 7342 bytes)
File: features.htm
Path : %programfiles%\netpumper\help

Md5Hash :6ba8810f9735dc0adcda3ec46fd9a5de ( 3570 bytes)
File: apllimit.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :94b5bdfc936407e92ea37ce1f22d33cd ( 626 bytes)
File: bandwidthpanel.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :35750e8d917f4de0618b4818cd04ca6a ( 2457 bytes)
File: buttons.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :a25083096979d90da41d8b025c992268 ( 3713 bytes)
File: cmdadd.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :813c2d6d5465ae4d913a2becb83e4cd5 ( 143 bytes)
File: cmdaddtoschedule.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :5eba7f2a8452fcef20d6ce5d247df25d ( 153 bytes)
File: cmddetails.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :0c356ed31e4dc7e0b029fc533de6de09 ( 117 bytes)
File: cmdeditschedule.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :e3f91dda98df5f53e467862b10e22154 ( 127 bytes)
File: cmdfolder.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :465a4a40a74bc0f4d75ff73d0a518519 ( 128 bytes)
File: cmdhelp.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :88de34d72e703b02a8450c920a1ebf01 ( 140 bytes)
File: cmdopen.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :27a028643581c770c327ed8ce17aec70 ( 129 bytes)
File: cmdopenfolder.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :5a75b6f89226916928f1be6db415ceec ( 127 bytes)
File: cmdpause.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :21646e8960e1b66383ae779e8732bb3d ( 103 bytes)
File: cmdprefs.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :66b35ab45fff4afc5f2a7ffb970cba90 ( 145 bytes)
File: cmdremove.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :a68f5b1a5657725f4f72b4d5889df563 ( 90 bytes)
File: cmdresume.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :5ae152f83bc5dea752b2b6920a50211b ( 92 bytes)
File: cmdselectall.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :1f1c2d691971dd2209f465a156fa3f56 ( 128 bytes)
File: detailwin.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :6464af59a95bc95e4673ec369b2c39ab ( 7938 bytes)
File: detailwin-wide.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :6af0f9b80f75e7b50d33f65970d57679 ( 9654 bytes)
File: droptoschedule.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :2b89d6e3c78220c32a4f04bd4b925d5e ( 905 bytes)
File: editbandwidth.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :e9c1939ca17f6548a7ceac69867fff88 ( 653 bytes)
File: ignlimit.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :ea9faa05cd2b5901274d56bcdc6a1c6e ( 627 bytes)
File: is-0j9jc.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :17d38084369279e658cbb8cf96bd4f0c ( bytes)
File: is-0ki3h.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :dac8e098400881f588c05ef6f010a1dc ( bytes)
File: is-0scnf.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :47bbf70870a46e5ceb100e356f22c1cd ( bytes)
File: is-1cm3v.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :27a028643581c770c327ed8ce17aec70 ( bytes)
File: is-1m9en.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :6464af59a95bc95e4673ec369b2c39ab ( bytes)
File: is-20g9o.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :36b518aec72d05908ccc3a9beb7cdf0f ( bytes)
File: is-256ou.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :e9c1939ca17f6548a7ceac69867fff88 ( bytes)
File: is-30hol.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :0c356ed31e4dc7e0b029fc533de6de09 ( bytes)
File: is-3j1ct.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :6a9481e40b3fab853a3acab66d8f072c ( bytes)
File: is-477oj.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :5bb9fbcf3d611d391d13313fec8c96ea ( bytes)
File: is-4l6og.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :a25083096979d90da41d8b025c992268 ( bytes)
File: is-50mhv.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :4832e0fc821e365a195369ae85483e81 ( bytes)
File: is-56g4d.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :5ae152f83bc5dea752b2b6920a50211b ( bytes)
File: is-5cm4h.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :35750e8d917f4de0618b4818cd04ca6a ( bytes)
File: is-5k76n.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :4622eb48800932c724687c3d4e551b24 ( bytes)
File: is-6hc4q.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :890d9887d67b933d729427d6fb1fdcf1 ( bytes)
File: is-74pui.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :1bf3c65f753d016c2de1c11a3b7e8f44 ( bytes)
File: is-9617k.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :6a736b74e8e503dba8427865eab5a852 ( bytes)
File: is-9gbsa.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :4756e3220bdc93cca7dcfa29d2d78e9f ( bytes)
File: is-9seae.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :813c2d6d5465ae4d913a2becb83e4cd5 ( bytes)
File: is-9t9fh.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :91e973ba4c0ab164654dadc3f3478a92 ( bytes)
File: is-a8f6e.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :0bf4e56c938457b69269d5455e3488d3 ( bytes)
File: is-bk59f.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :6af0f9b80f75e7b50d33f65970d57679 ( bytes)
File: is-d6m1k.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :4c5c1ae0f42620abec1ad4b6672b09d3 ( bytes)
File: is-e2o9q.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :ea9faa05cd2b5901274d56bcdc6a1c6e ( bytes)
File: is-ebona.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :21646e8960e1b66383ae779e8732bb3d ( bytes)
File: is-ehuqe.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :1751e6b480ba68fb4a48705e5c6ba6fb ( bytes)
File: is-ek8mv.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :7f72bac9c22ac244b6d55df15102e15a ( bytes)
File: is-felri.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :8840700b642fcab3d6b58805cbd79e27 ( bytes)
File: is-fqho5.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :2b89d6e3c78220c32a4f04bd4b925d5e ( bytes)
File: is-ggs0v.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :b8dd9d786f169058d8c272df29bb460c ( bytes)
File: is-ghc3q.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :94b5bdfc936407e92ea37ce1f22d33cd ( bytes)
File: is-gp5rm.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :732788f871ac706c95c1d00361f811a5 ( bytes)
File: is-ha5o3.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :600548dce73169a0e421b47b00bdd346 ( bytes)
File: is-htenf.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :6b25bfbf2f6ddc308727653e55c391a5 ( bytes)
File: is-jc2e6.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :66b35ab45fff4afc5f2a7ffb970cba90 ( bytes)
File: is-jpkd5.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :3d0b762b9b0af5fbe8da74588da49e3b ( bytes)
File: is-jsqt1.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :5eba7f2a8452fcef20d6ce5d247df25d ( bytes)
File: is-k5u18.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :c38748e15afcba294c9edf7199d76fd9 ( bytes)
File: is-kecr9.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :e3f91dda98df5f53e467862b10e22154 ( bytes)
File: is-ks9l3.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :e8804d22619c9cfd3323e25e8eab4b51 ( bytes)
File: is-lv37c.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :a34754f95f3b0fd933d4e3551485f470 ( bytes)
File: is-mqi6f.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :f1c6b0e117fe339abc68dcaf18ef0696 ( bytes)
File: is-o4afr.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :a68f5b1a5657725f4f72b4d5889df563 ( bytes)
File: is-p0406.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :b90f3c9be125f0570a3198534d9c3b08 ( bytes)
File: is-p4add.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :5a75b6f89226916928f1be6db415ceec ( bytes)
File: is-p6u3i.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :88de34d72e703b02a8450c920a1ebf01 ( bytes)
File: is-pbkrr.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :7d10466dc0394fc8795617acaebc6891 ( bytes)
File: is-qb44v.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :a3885c311cafb7c4bb3190d9257f99c5 ( bytes)
File: is-r1ubl.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :bf6b74092972d2ae0fd5bf304bdd918b ( bytes)
File: is-r3m8b.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :aa42269d4353e29b599797127954fe41 ( bytes)
File: is-s9opu.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :b00ae032032e6079e93ed6e27c7e2d92 ( bytes)
File: is-sdpp0.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :ba49757e38fb7f920ef9c3e062c9c8b8 ( bytes)
File: is-ui78d.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :1f1c2d691971dd2209f465a156fa3f56 ( bytes)
File: is-uivpu.tmp
Path : %programfiles%\netpumper\help\images

Md5Hash :465a4a40a74bc0f4d75ff73d0a518519 ( bytes)
File: limserver.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :8840700b642fcab3d6b58805cbd79e27 ( 98 bytes)
File: limservergold.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :0bf4e56c938457b69269d5455e3488d3 ( 104 bytes)
File: limuser.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :890d9887d67b933d729427d6fb1fdcf1 ( 112 bytes)
File: mainwin.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :47bbf70870a46e5ceb100e356f22c1cd ( 36373 bytes)
File: moveicons.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :f1c6b0e117fe339abc68dcaf18ef0696 ( 1086 bytes)
File: prefw-bandwidth.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :ba49757e38fb7f920ef9c3e062c9c8b8 ( 11123 bytes)
File: prefw-connections.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :4622eb48800932c724687c3d4e551b24 ( 9856 bytes)
File: prefw-general.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :a34754f95f3b0fd933d4e3551485f470 ( 8401 bytes)
File: prefw-login.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :c38748e15afcba294c9edf7199d76fd9 ( 8999 bytes)
File: prefw-monitoring.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :b00ae032032e6079e93ed6e27c7e2d92 ( 11484 bytes)
File: prefw-proxy-ftp.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :36b518aec72d05908ccc3a9beb7cdf0f ( 10045 bytes)
File: prefw-proxy-http.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :4832e0fc821e365a195369ae85483e81 ( 9934 bytes)
File: register-1.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :7f72bac9c22ac244b6d55df15102e15a ( 8883 bytes)
File: register-2.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :1bf3c65f753d016c2de1c11a3b7e8f44 ( 8417 bytes)
File: register-3-1.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :732788f871ac706c95c1d00361f811a5 ( 10455 bytes)
File: register-3-2.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :4c5c1ae0f42620abec1ad4b6672b09d3 ( 17976 bytes)
File: schedulewin.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :600548dce73169a0e421b47b00bdd346 ( 24293 bytes)
File: scnoresume.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :b90f3c9be125f0570a3198534d9c3b08 ( 92 bytes)
File: scresumes.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :1751e6b480ba68fb4a48705e5c6ba6fb ( 72 bytes)
File: scunk.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :aa42269d4353e29b599797127954fe41 ( 80 bytes)
File: stanalyzing.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :a3885c311cafb7c4bb3190d9257f99c5 ( 87 bytes)
File: starticon.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :5bb9fbcf3d611d391d13313fec8c96ea ( 291 bytes)
File: stcompleted.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :3d0b762b9b0af5fbe8da74588da49e3b ( 104 bytes)
File: stfatal.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :6a9481e40b3fab853a3acab66d8f072c ( 136 bytes)
File: stinpro.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :b8dd9d786f169058d8c272df29bb460c ( 97 bytes)
File: stnhelp.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :91e973ba4c0ab164654dadc3f3478a92 ( 108 bytes)
File: stopicon.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :17d38084369279e658cbb8cf96bd4f0c ( 516 bytes)
File: stpaused.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :bf6b74092972d2ae0fd5bf304bdd918b ( 105 bytes)
File: stqueued.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :dac8e098400881f588c05ef6f010a1dc ( 163 bytes)
File: stretrying.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :7d10466dc0394fc8795617acaebc6891 ( 105 bytes)
File: stscheduled.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :6a736b74e8e503dba8427865eab5a852 ( 125 bytes)
File: summary.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :e8804d22619c9cfd3323e25e8eab4b51 ( 1020 bytes)
File: throtdn.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :4756e3220bdc93cca7dcfa29d2d78e9f ( 624 bytes)
File: zoombtn.gif
Path : %programfiles%\netpumper\help\images

Md5Hash :6b25bfbf2f6ddc308727653e55c391a5 ( 992 bytes)
File: index.htm
Path : %programfiles%\netpumper\help

Md5Hash :80ac088151e6319b2de9524ccedd4b26 ( 7787 bytes)
File: is-0io3v.tmp
Path : %programfiles%\netpumper\help

Md5Hash :a65f4848187542c444c91203da14bf57 ( bytes)
File: is-2bqbt.tmp
Path : %programfiles%\netpumper\help

Md5Hash :0b0bd4df133981c2dbb7ed6d33e150dd ( bytes)
File: is-2oc5m.tmp
Path : %programfiles%\netpumper\help

Md5Hash :496cff5ceb198ad783f51f0cdde4fb46 ( bytes)
File: is-69fbn.tmp
Path : %programfiles%\netpumper\help

Md5Hash :7e29d7797d0ba4bdc70c8f221273ad5e ( bytes)
File: is-7ei98.tmp
Path : %programfiles%\netpumper\help

Md5Hash :6ba8810f9735dc0adcda3ec46fd9a5de ( bytes)
File: is-8fvr6.tmp
Path : %programfiles%\netpumper\help

Md5Hash :80ac088151e6319b2de9524ccedd4b26 ( bytes)
File: is-9jag6.tmp
Path : %programfiles%\netpumper\help

Md5Hash :a9efcc2a88f431f500c189f3141edf8e ( bytes)
File: is-fafg2.tmp
Path : %programfiles%\netpumper\help

Md5Hash :a752522c7da2bac69e35adfe9f179321 ( bytes)
File: is-ohfj7.tmp
Path : %programfiles%\netpumper\help

Md5Hash :4f71c26f9b43d7e85a1bcddfeb49ee28 ( bytes)
File: is-t0ph2.tmp
Path : %programfiles%\netpumper\help

Md5Hash :43a65588f58147dca1f46c2a9f06ceb1 ( bytes)
File: mainwin.htm
Path : %programfiles%\netpumper\help

Md5Hash :43a65588f58147dca1f46c2a9f06ceb1 ( 40835 bytes)
File: nphelp.css
Path : %programfiles%\netpumper\help

Md5Hash :a65f4848187542c444c91203da14bf57 ( 178 bytes)
File: prefwindow.htm
Path : %programfiles%\netpumper\help

Md5Hash :a752522c7da2bac69e35adfe9f179321 ( 31958 bytes)
File: register.htm
Path : %programfiles%\netpumper\help

Md5Hash :496cff5ceb198ad783f51f0cdde4fb46 ( 9561 bytes)
File: schedwin.htm
Path : %programfiles%\netpumper\help

Md5Hash :a9efcc2a88f431f500c189f3141edf8e ( 14183 bytes)
File: tips.htm
Path : %programfiles%\netpumper\help

Md5Hash :7e29d7797d0ba4bdc70c8f221273ad5e ( 30219 bytes)
File: is-1uq2m.tmp
Path : %programfiles%\netpumper

Md5Hash :658b706c663787ed10487902602ff17a ( bytes)
File: is-4rm3u.tmp
Path : %programfiles%\netpumper

Md5Hash :682f40892232577b48f06f5a9ddb97c9 ( bytes)
File: is-4suvo.tmp
Path : %programfiles%\netpumper

Md5Hash :904eb47099d8e7c39ef1c41d5cf3a7c1 ( bytes)
File: is-82ckm.tmp
Path : %programfiles%\netpumper

Md5Hash :bbf6573871ce8451338ee0c76d6cf7e2 ( bytes)
File: is-c0hnv.tmp
Path : %programfiles%\netpumper

Md5Hash :034cc852d5bfe5c66f9c9d469f4d0dab ( bytes)
File: is-dlndm.tmp
Path : %programfiles%\netpumper

Md5Hash :b23467201bd003299f3bca3ada0e3f8b ( bytes)
File: is-es1a7.tmp
Path : %programfiles%\netpumper

Md5Hash :9bd23b0bf17457bdef5bc0e4b2c15fc1 ( bytes)
File: is-fgvi0.tmp
Path : %programfiles%\netpumper

Md5Hash :3da026d3b7e355f1c447e15a73e5ea3d ( bytes)
File: is-g3nrc.tmp
Path : %programfiles%\netpumper

Md5Hash :ab7e0cba56dddff86b9de9ce62f9e1e9 ( bytes)
File: is-jruet.tmp
Path : %programfiles%\netpumper

Md5Hash :dced251e98434d650a54ac033bf05176 ( bytes)
File: is-lh1nq.tmp
Path : %programfiles%\netpumper

Md5Hash :189586e1aa8eed81e3e94ddc67410f88 ( bytes)
File: is-lptsi.tmp
Path : %programfiles%\netpumper

Md5Hash :8c76e89e441f733e73f3f128b8406542 ( bytes)
File: is-r9dri.tmp
Path : %programfiles%\netpumper

Md5Hash :c6ab31ac217d382f0008e7b9b2704a95 ( bytes)
File: netpumper.exe
Path : %programfiles%\netpumper

Md5Hash :ab7e0cba56dddff86b9de9ce62f9e1e9 ( 2396672 bytes)
File: netpumperieproxy.exe
Path : %programfiles%\netpumper

Md5Hash :9bd23b0bf17457bdef5bc0e4b2c15fc1 ( 704000 bytes)
File: netpumpernnproxy.dll
Path : %programfiles%\netpumper

Md5Hash :189586e1aa8eed81e3e94ddc67410f88 ( 648192 bytes)
File: npnetpumper_application.dll
Path : %programfiles%\netpumper

Md5Hash :b23467201bd003299f3bca3ada0e3f8b ( 124928 bytes)
File: npnetpumper_audio.dll
Path : %programfiles%\netpumper

Md5Hash :8c76e89e441f733e73f3f128b8406542 ( 124416 bytes)
File: npnetpumper_video.dll
Path : %programfiles%\netpumper

Md5Hash :bbf6573871ce8451338ee0c76d6cf7e2 ( 124416 bytes)
File: readme.txt
Path : %programfiles%\netpumper

Md5Hash :dced251e98434d650a54ac033bf05176 ( 14539 bytes)
File: rsqwww2.exe
Path : %programfiles%\netpumper

Md5Hash :658b706c663787ed10487902602ff17a ( 178970 bytes)
File: shutdown.exe
Path : %programfiles%\netpumper

Md5Hash :c6ab31ac217d382f0008e7b9b2704a95 ( 114176 bytes)
File: turnlog.exe
Path : %programfiles%\netpumper

Md5Hash :3da026d3b7e355f1c447e15a73e5ea3d ( 486400 bytes)
File: unins000.dat
Path : %programfiles%\netpumper

Md5Hash :fdf95c6ae6b8788c88b14402141ec4fb ( 8424 bytes)
File: x.bat
Path : %programfiles%\netpumper

Md5Hash :904eb47099d8e7c39ef1c41d5cf3a7c1 ( 36 bytes)
File: is-itkmf.tmp
Path : %programfiles%\netpumper\zm

Md5Hash :de41c0dde482859f70b6168e5c351179 ( bytes)
File: minime.exe
Path : %programfiles%\netpumper\zm

Md5Hash :de41c0dde482859f70b6168e5c351179 ( 312320 bytes)
File: cl.exe
Path : %systemdrive%

Md5Hash :9d993f5cf2dbdf1a2224fb0b0d4404e1 ( 41984 bytes)
File: bis64.exe
Path : %temp%

Md5Hash :3320f9422738b34d751c321bd76f7e96 ( 481280 bytes)
File: htmlcontrol.dll
Path : %temp%\is-7geas.tmp

Md5Hash :fb2fa93c354ebe38b0642c61e2551b73 ( bytes)
File: license.bmp
Path : %temp%\is-7geas.tmp

Md5Hash :b0165ac2cec644f58bba9ddf66c35d44 ( bytes)
File: license.txt
Path : %temp%\is-7geas.tmp

Md5Hash :222227c7b6b49e2ee9eaf9faad768be8 ( bytes)
File: bundles.dll
Path : %temp%\is-p5l28.tmp

Md5Hash :991fd8b4c064481c93feb8441774c749 ( bytes)
File: is-583db.tmp
Path : %temp%\is-p5l28.tmp

Md5Hash :731764f5ca4461c01bdb043f6075d24f ( bytes)
File: is-590rt.tmp
Path : %temp%\is-p5l28.tmp

Md5Hash :8f5eececd6cc649f0869fbb0cba0cbd8 ( bytes)
File: lightcertgen.exe
Path : %temp%\is-p5l28.tmp

Md5Hash :( bytes)
File: setcertacl.exe
Path : %temp%\is-p5l28.tmp

Md5Hash :( bytes)
File: processwork.dll
Path : %temp%\nsw6b.tmp

Md5Hash :0a4fa7a9ba969a805eb0603c7cfe3378 ( bytes)
File: [randomname].exe
Path : %workingdir%

Skip Navigation Links.
Collapse Md5Hash :Md5Hash :
001e823b3bcd846537f656251efd1ae5 ( 1544328 bytes)
060cd5d5a7a187cd069fb168a26654bf ( 3755528 bytes)
de41c0dde482859f70b6168e5c351179 ( 312320 bytes)
Also creates the following files on user's System which are also created by Genuine Software :-
Note:
These file(s) can be kept as they are also created by genuine Software.
File : desktop.ini
Path : %homepath%\my documents

Md5Hash :869cba0364c55b0c6524419a8b86df88 ( 83 bytes)
File : desktop.ini
Path : %homepath%\my documents\my pictures

Md5Hash :f958dc73dc27ae8589bc1b1dfbd18e4a ( 190 bytes)
File : unins000.exe
Path : %programfiles%\netpumper

Md5Hash :d8dc6a4d444afd5d2c0be529ea4b6a25 ( 72884 bytes)
File : ins1.tmp
Path : %temp%

Md5Hash :191933112bf619537981d42c851e9b75 ( bytes)
File : _regdll.tmp
Path : %temp%\is-7geas.tmp\_isetup

Md5Hash :c594b792b9c556ea62a30de541d2fb03 ( bytes)
File : _shfoldr.dll
Path : %temp%\is-7geas.tmp\_isetup

Md5Hash :92dc6ef532fbb4a5c3201469a5b5eb63 ( bytes)
File : 001e823b3bcd846537f656251efd1ae5.tmp
Path : %temp%\is-jr0ld.tmp

Md5Hash :9e30ab5e3f6b43f69f928e6b4fcfd604 ( bytes)
File : _shfoldr.dll
Path : %temp%\is-p5l28.tmp

Md5Hash :92dc6ef532fbb4a5c3201469a5b5eb63 ( bytes)
File : desktop.ini
Path : %userprofile%\application data

Md5Hash :88cf0ff92a4a9fa7bd9b7513b2e9e22b ( 62 bytes)
File : desktop.ini
Path : %userprofile%\start menu

Md5Hash :87f8888e1d77d9cef69e901a97d40d73 ( 62 bytes)
File : desktop.ini
Path : %userprofile%\start menu\programs

Md5Hash :e694dc03fb0f8b5b3f3a38ccefec8b3c ( 234 bytes)
Creates the following infected Registry Keys on user's System
Note:
Delete these Registries to remove Infection
The following Registry Values are added to the provided Registry Keys :-
Note:
Delete the added Values from the Key to remove Infection
|__ Value Added :
start page = "http://www2.iesearch.com/"
|__ Value Added :
contexts = "[reg_dword, value: 000000f3]"
|__ Value Added :
content type = "application/x-netpumper-detector"
|__ Value Added :
local page = "http://www2.iesearch.com/"
|__ Value Added :
netpumper = ""%programfiles%\netpumper\netpumperieproxy.exe""
|__ Value Added :
displayname = "netpumper 1.50"
|__ Value Added :
inno setup: app path = "%programfiles%\netpumper"
|__ Value Added :
inno setup: deselected components = ""
|__ Value Added :
inno setup: icon group = "netpumper"
|__ Value Added :
inno setup: selected components = "netpumper"
|__ Value Added :
inno setup: setup type = "standard"
|__ Value Added :
inno setup: setup version = "2.0.18 with isx 2.0.18"
|__ Value Added :
inno setup: user = "antispyclone"
|__ Value Added :
uninstallstring = ""%programfiles%\netpumper\unins000.exe""
|__ Value Added :
application = "netpumper"
|__ Value Added :
newver = "http://cv.netpumper.com/"
|__ Value Added :
versioninfo = "yfsaag4p-a0vjg9wfvufj1b8sz+zb6s29+mmaj7xnc76sctmimhwgmxdz7guughbaf-+a2qdiyd6uky0tbtg5pegabjg4fdro4f++nbgwgeypsyf-kszpgcrzycklqcvtyqosq4qq7jvdzszii3ratjmcehazbs4wgex89w0svo"
|__ Value Added :
state = "[reg_dword, value: 00000000]"
Also creates the following legitmate Registries on user's Systems which are also created by Genuine Software :-
Note:
These Keys can be kept as they are also created by genuine Software
The following Registry Values are added to the provided Registry Keys which are also created by Genuine Software :-
Note:
These Values can be left as they are also created by legitimate Software :-
Creates the following child process(s) on execution:

%systemdrive%\docume~1\antisp~1\locals~1\temp\ins1.tmp /sl3 $10182 %workingdir%\[random name].exe 3730042 3733475 61440 /silent /s /s /qn /sp- /passive -s -s

services.exe

%programfiles%\netpumper\zm\minime.exe 7b7b0def0110efe7123

%programfiles%\internet explorer\iexplore.exe

%programfiles%\netpumper\rsqwww2.exe

%systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\setcertacl.exe

%systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\lightcertgen.exe netpumper

%programfiles%\netpumper\netpumper.exe /regserver

%windir%\system32\regsvr32 /s netpumpernnproxy.dll

%programfiles%\netpumper\netpumperieproxy.exe

%programfiles%\internet explorer\iexplore.exe http://www.netpumper.com/index.php?go=installed

%windir%\system32\notepad.exe %programfiles%\netpumper\readme.txt

%systemdrive%\docume~1\antisp~1\locals~1\temp\bis64.exe -curl 7b7b123 -mpxnp_0246

Creates the Following MUTEX(s) on user's System:-
fdfd57ae
raspbfile
Tries To Connect to The Following Urls:-
Http_Version :http/1.1
66.220.17.200/bins/int/np_pkz.int?affid=np_0246&fxp=81b7a0d3db23980cbaf7c596925a778588a77597a5fc7afb32b385046401c596e5b66545
Moves the Following Files to Given Location :-
Moves :%programfiles%\netpumper\is-c0hnv.tmp
To : %programfiles%\netpumper\unins000.exe
Moves :%programfiles%\netpumper\is-4suvo.tmp
To : %programfiles%\netpumper\x.bat
Moves :%programfiles%\netpumper\is-jruet.tmp
To : %programfiles%\netpumper\readme.txt
Moves :%programfiles%\netpumper\is-4rm3u.tmp
To : %programfiles%\netpumper\addurl.htm
Moves :%programfiles%\netpumper\is-g3nrc.tmp
To : %programfiles%\netpumper\netpumper.exe
Moves :%programfiles%\netpumper\is-lh1nq.tmp
To : %programfiles%\netpumper\netpumpernnproxy.dll
Moves :%programfiles%\netpumper\is-es1a7.tmp
To : %programfiles%\netpumper\netpumperieproxy.exe
Moves :%programfiles%\netpumper\is-r9dri.tmp
To : %programfiles%\netpumper\shutdown.exe
Moves :%programfiles%\netpumper\is-lptsi.tmp
To : %programfiles%\netpumper\npnetpumper_audio.dll
Moves :%programfiles%\netpumper\is-82ckm.tmp
To : %programfiles%\netpumper\npnetpumper_video.dll
Moves :%programfiles%\netpumper\is-dlndm.tmp
To : %programfiles%\netpumper\npnetpumper_application.dll
Moves :%programfiles%\netpumper\help\is-2bqbt.tmp
To : %programfiles%\netpumper\help\compat.htm
Moves :%programfiles%\netpumper\help\is-7ei98.tmp
To : %programfiles%\netpumper\help\features.htm
Moves :%programfiles%\netpumper\help\is-8fvr6.tmp
To : %programfiles%\netpumper\help\index.htm
Moves :%programfiles%\netpumper\help\is-t0ph2.tmp
To : %programfiles%\netpumper\help\mainwin.htm
Moves :%programfiles%\netpumper\help\is-69fbn.tmp
To : %programfiles%\netpumper\help\tips.htm
Moves :%programfiles%\netpumper\help\is-ohfj7.tmp
To : %programfiles%\netpumper\help\details.htm
Moves :%programfiles%\netpumper\help\is-0io3v.tmp
To : %programfiles%\netpumper\help\nphelp.css
Moves :%programfiles%\netpumper\help\is-fafg2.tmp
To : %programfiles%\netpumper\help\prefwindow.htm
Moves :%programfiles%\netpumper\help\is-2oc5m.tmp
To : %programfiles%\netpumper\help\register.htm
Moves :%programfiles%\netpumper\help\is-9jag6.tmp
To : %programfiles%\netpumper\help\schedwin.htm
Moves :%programfiles%\netpumper\help\images\is-pbkrr.tmp
To : %programfiles%\netpumper\help\images\stretrying.gif
Moves :%programfiles%\netpumper\help\images\is-9seae.tmp
To : %programfiles%\netpumper\help\images\cmdadd.gif
Moves :%programfiles%\netpumper\help\images\is-30hol.tmp
To : %programfiles%\netpumper\help\images\cmddetails.gif
Moves :%programfiles%\netpumper\help\images\is-uivpu.tmp
To : %programfiles%\netpumper\help\images\cmdfolder.gif
Moves :%programfiles%\netpumper\help\images\is-p6u3i.tmp
To : %programfiles%\netpumper\help\images\cmdhelp.gif
Moves :%programfiles%\netpumper\help\images\is-1cm3v.tmp
To : %programfiles%\netpumper\help\images\cmdopen.gif
Moves :%programfiles%\netpumper\help\images\is-ebona.tmp
To : %programfiles%\netpumper\help\images\cmdpause.gif
Moves :%programfiles%\netpumper\help\images\is-jc2e6.tmp
To : %programfiles%\netpumper\help\images\cmdprefs.gif
Moves :%programfiles%\netpumper\help\images\is-o4afr.tmp
To : %programfiles%\netpumper\help\images\cmdremove.gif
Moves :%programfiles%\netpumper\help\images\is-56g4d.tmp
To : %programfiles%\netpumper\help\images\cmdresume.gif
Moves :%programfiles%\netpumper\help\images\is-ui78d.tmp
To : %programfiles%\netpumper\help\images\cmdselectall.gif
Moves :%programfiles%\netpumper\help\images\is-1m9en.tmp
To : %programfiles%\netpumper\help\images\detailwin.gif
Moves :%programfiles%\netpumper\help\images\is-bk59f.tmp
To : %programfiles%\netpumper\help\images\detailwin-wide.gif
Moves :%programfiles%\netpumper\help\images\is-0scnf.tmp
To : %programfiles%\netpumper\help\images\mainwin.gif
Moves :%programfiles%\netpumper\help\images\is-5k76n.tmp
To : %programfiles%\netpumper\help\images\prefw-connections.gif
Moves :%programfiles%\netpumper\help\images\is-k5u18.tmp
To : %programfiles%\netpumper\help\images\prefw-login.gif
Moves :%programfiles%\netpumper\help\images\is-jpkd5.tmp
To : %programfiles%\netpumper\help\images\stcompleted.gif
Moves :%programfiles%\netpumper\help\images\is-3j1ct.tmp
To : %programfiles%\netpumper\help\images\stfatal.gif
Moves :%programfiles%\netpumper\help\images\is-ggs0v.tmp
To : %programfiles%\netpumper\help\images\stinpro.gif
Moves :%programfiles%\netpumper\help\images\is-9t9fh.tmp
To : %programfiles%\netpumper\help\images\stnhelp.gif
Moves :%programfiles%\netpumper\help\images\is-r1ubl.tmp
To : %programfiles%\netpumper\help\images\stpaused.gif
Moves :%programfiles%\netpumper\help\images\is-4l6og.tmp
To : %programfiles%\netpumper\help\images\buttons.gif
Moves :%programfiles%\netpumper\help\images\is-s9opu.tmp
To : %programfiles%\netpumper\help\images\prefw-monitoring.gif
Moves :%programfiles%\netpumper\help\images\is-lv37c.tmp
To : %programfiles%\netpumper\help\images\prefw-general.gif
Moves :%programfiles%\netpumper\help\images\is-20g9o.tmp
To : %programfiles%\netpumper\help\images\prefw-proxy-ftp.gif
Moves :%programfiles%\netpumper\help\images\is-50mhv.tmp
To : %programfiles%\netpumper\help\images\prefw-proxy-http.gif
Moves :%programfiles%\netpumper\help\images\is-r3m8b.tmp
To : %programfiles%\netpumper\help\images\scunk.gif
Moves :%programfiles%\netpumper\help\images\is-ehuqe.tmp
To : %programfiles%\netpumper\help\images\scresumes.gif
Moves :%programfiles%\netpumper\help\images\is-p0406.tmp
To : %programfiles%\netpumper\help\images\scnoresume.gif
Moves :%programfiles%\netpumper\help\images\is-ks9l3.tmp
To : %programfiles%\netpumper\help\images\summary.gif
Moves :%programfiles%\netpumper\help\images\is-ek8mv.tmp
To : %programfiles%\netpumper\help\images\register-1.gif
Moves :%programfiles%\netpumper\help\images\is-74pui.tmp
To : %programfiles%\netpumper\help\images\register-2.gif
Moves :%programfiles%\netpumper\help\images\is-gp5rm.tmp
To : %programfiles%\netpumper\help\images\register-3-1.gif
Moves :%programfiles%\netpumper\help\images\is-d6m1k.tmp
To : %programfiles%\netpumper\help\images\register-3-2.gif
Moves :%programfiles%\netpumper\help\images\is-5cm4h.tmp
To : %programfiles%\netpumper\help\images\bandwidthpanel.gif
Moves :%programfiles%\netpumper\help\images\is-p4add.tmp
To : %programfiles%\netpumper\help\images\cmdopenfolder.gif
Moves :%programfiles%\netpumper\help\images\is-jsqt1.tmp
To : %programfiles%\netpumper\help\images\cmdaddtoschedule.gif
Moves :%programfiles%\netpumper\help\images\is-kecr9.tmp
To : %programfiles%\netpumper\help\images\cmdeditschedule.gif
Moves :%programfiles%\netpumper\help\images\is-ghc3q.tmp
To : %programfiles%\netpumper\help\images\apllimit.gif
Moves :%programfiles%\netpumper\help\images\is-6hc4q.tmp
To : %programfiles%\netpumper\help\images\limuser.gif
Moves :%programfiles%\netpumper\help\images\is-256ou.tmp
To : %programfiles%\netpumper\help\images\editbandwidth.gif
Moves :%programfiles%\netpumper\help\images\is-e2o9q.tmp
To : %programfiles%\netpumper\help\images\ignlimit.gif
Moves :%programfiles%\netpumper\help\images\is-felri.tmp
To : %programfiles%\netpumper\help\images\limserver.gif
Moves :%programfiles%\netpumper\help\images\is-a8f6e.tmp
To : %programfiles%\netpumper\help\images\limservergold.gif
Moves :%programfiles%\netpumper\help\images\is-fqho5.tmp
To : %programfiles%\netpumper\help\images\droptoschedule.gif
Moves :%programfiles%\netpumper\help\images\is-sdpp0.tmp
To : %programfiles%\netpumper\help\images\prefw-bandwidth.gif
Moves :%programfiles%\netpumper\help\images\is-mqi6f.tmp
To : %programfiles%\netpumper\help\images\moveicons.gif
Moves :%programfiles%\netpumper\help\images\is-ha5o3.tmp
To : %programfiles%\netpumper\help\images\schedulewin.gif
Moves :%programfiles%\netpumper\help\images\is-htenf.tmp
To : %programfiles%\netpumper\help\images\zoombtn.gif
Moves :%programfiles%\netpumper\help\images\is-477oj.tmp
To : %programfiles%\netpumper\help\images\starticon.gif
Moves :%programfiles%\netpumper\help\images\is-0j9jc.tmp
To : %programfiles%\netpumper\help\images\stopicon.gif
Moves :%programfiles%\netpumper\help\images\is-0ki3h.tmp
To : %programfiles%\netpumper\help\images\stqueued.gif
Moves :%programfiles%\netpumper\help\images\is-9617k.tmp
To : %programfiles%\netpumper\help\images\stscheduled.gif
Moves :%programfiles%\netpumper\help\images\is-9gbsa.tmp
To : %programfiles%\netpumper\help\images\throtdn.gif
Moves :%programfiles%\netpumper\help\images\is-qb44v.tmp
To : %programfiles%\netpumper\help\images\stanalyzing.gif
Moves :%programfiles%\netpumper\zm\is-itkmf.tmp
To : %programfiles%\netpumper\zm\minime.exe
Moves :%systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\is-583db.tmp
To : %systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\setcertacl.exe
Moves :%systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\is-590rt.tmp
To : %systemdrive%\docume~1\antisp~1\locals~1\temp\is-p5l28.tmp\lightcertgen.exe
Moves :%programfiles%\netpumper\is-fgvi0.tmp
To : %programfiles%\netpumper\turnlog.exe
Moves :%programfiles%\netpumper\is-1uq2m.tmp
To : %programfiles%\netpumper\rsqwww2.exe

NOTE:

1. %allusersprofile% Refers to the windows all users profile folder. By default it is 'C:\Documents and Settings\All Users'
2. %programfiles% Refers to the program files folder. By default it is 'C:\Program Files'
3. %systemdrive% Refers to the windows System drive folder. By default it is 'C:\'
4. %temp% Refers to the windows temp folder. By default it is 'C:\Documents and Settings\[user]\Local Settings\Temp'
5. %userprofile% Refers to the windows current user's profile folder. By default it is 'C:\Documents and Settings\[user]'
6. %workingdir% Refers to the current directory in which user is working.
7. %homepath% Refers to the windows current user's profile folder. By default it is 'C:\Documents and Settings\[user]'

Important: We strongly recommend that you backup the Registry before making any changes to it. Incorrect changes to the Registry can result in permanent data loss or corrupted Files. Modify the malicious\suspicious Subkeys only.

Click Here for more spywarelib.com recommended PC Security and Optimization Tools

To modify registry entries in Windows Operating System:
Follow Steps:
1. Click Start > Run
2. Type “regedit” : to open registry editor
3. Navigate to required registry Key from the Left Tree control and modify accordingly.


Microsoft Gold Certified Partner

© Systweak Inc., 1999-2009 All rights reserved.