GetNet

Classification

Malware

-

-

GetNet, Backdoor.GetNet

Summary

F-Secure Anti-Virus detects Backdoor.GetNet in a browser plugin that was created by iGetNet to aid Internet search. The plugin can be downloaded from www.igetnet.com website by clicking 'Try Demo' button.

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

Originally detection of this plugin was added because the plugin's behaviour is malware-like: it is installed to user's system without confirmation and without showing a licence agreement, it can by itself download and run files on user's computer.

The GetNet plugin is distributed inside an installation package that is downloaded and activated on a computer when a user clicks certain area on IGetNet website. The installer drops the main plugin's file to a hard drive without showing any licence agreement or asking confimation from a user. The GetNet plugin's main file is dropped to Windows System folder as Winstart001.exe file and the special Registry key is created to make sure that the plugin's file is started during every Windows session:

[HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run]
"WinStart001.exe" = "%WinSysDir%\WinStart001.exe -b"

where %WinSysDir% represents Windows System Directory.

The creator of the GetNet plugin provides uninstallation module for it. If you want to uninstall the plugin from your computer, you can download the uninstaller from here:

https://www.igetnet.com/downloads/uninstall_igetnet.asp

Date Created: -

Date Last Modified: -