Threat description




A dropper Trojan that contains malicious or potentially unwanted software, which it 'drops' and installs on the affected system.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

Binanen.A creates a dummy iexplore.exe process, and runs its malicious activity by silently dropping the following file:

  • C:\windows\system32\winimet.dll

It also copies itself to:

  • C:\windows\system32\binanen.exe

And, creates the following registry keys:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{26D37492-FEC2-C272-9882-6D97A521F122}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{761CC820-6EC0-5921-1400-8442C1E2FB90}


Once the malware is executed, the dropped file will try to disguise itself under a true process name and will be injected into a hidden dummy process. Then, it will execute certain command lines such asipconfig, which can be used to retrieve IP address, subnet mask, and default gateway.

Once the DLL file has been injected and running under the hidden Internet Explorer process, the attacker will be able to control the infected machine and retrieve information such as list of processes and hard disk information from the affected machine. The attacker could also obtain data such as username, system date and time, and how long the machine has been up and running.

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info