Home Malware Programs Remote Administration Tools NetSpy (DK32)

NetSpy (DK32)

Posted: March 28, 2006

This is a Remote Administration Tool that is used by hackers to control the victim's machine remotely. The possibilities of such applications depend on the needs of the attacker. The attacker infects the PC via the e-mail or File and Print Sharing. A "server" allows him to connect via a "client" on his own machine. The functions of a RAT may vary, depending on the needs of the hacker. Some RATs can't really harm your PC and the only purpose they were made for is hooliganism. But some versions can steal vital information, remove files and even crash your computer. The author of this RAT is a hacker called DK32. Many versions appeared from November 1996 to May 2004.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 file_id.diz
    2 netdd.exe
    3 netspy 1.06.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunxload32
Loading...