Home Malware Programs Trojans Netsnak.b

Netsnak.b

Posted: March 28, 2006

Netsnak.b is a trojan that searches local hard drives for files containing many passwords and login names in order to steal them. Gathered data is sent to a predetermined e-mail address. The spyware also silently downloads from the Internet and executes arbitrary files, some of them may carry a destructive payload. Netsnak.b automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winsrv.exe
    2 winsrvhk.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinsrv
Loading...