W32/Neeris-R exhibits the following characteristics:
File Information
- Size
- 124K
- SHA-1
- 9d769da87edfe0892c99479c62fff1e89fef177d
- MD5
- 4bfab01c488353f08abf2e25245210af
- CRC-32
- f24b90b4
- File type
- Windows executable
- First seen
- 2011-03-12
Other vendor detection
- Kaspersky
- Trojan.Win32.Menti.hgx
- Trend
- TROJ_MENTI.AK
Runtime Analysis
Copies Itself To
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
- Service Noits
- xanga.exe
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Service Noits
- xanga.exe
- HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- c:\test_item.exe
- c:\test_item.exe:*:Enabled:Service Noits
Registry Keys Modified
- HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\Performance
- Error Count
- 0x0000000a
Processes Created
- c:\windows\system32\netsh.exe