W32/Neeris-R

Category: Viruses and Spyware Protection available since:06 Apr 2012 14:29:19 (GMT)
Type: Win32 worm Last Updated:06 Apr 2012 14:29:19 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Neeris-R exhibits the following characteristics:

File Information

Size
124K
SHA-1
9d769da87edfe0892c99479c62fff1e89fef177d
MD5
4bfab01c488353f08abf2e25245210af
CRC-32
f24b90b4
File type
Windows executable
First seen
2011-03-12

Other vendor detection

Kaspersky
Trojan.Win32.Menti.hgx
Trend
TROJ_MENTI.AK

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\xanga.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
    Service Noits
    xanga.exe
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    Service Noits
    xanga.exe
  • HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    c:\test_item.exe
    c:\test_item.exe:*:Enabled:Service Noits
Registry Keys Modified
  • HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\Performance
    Error Count
    0x0000000a
Processes Created
  • c:\windows\system32\netsh.exe

download Try Sophos products for free
Download now