Threat Description

GetNet

Details

Category: Malware
Platform: W32
Aliases: GetNet, Backdoor.GetNet

Summary


F-Secure Anti-Virus detects Backdoor.GetNet in a browser plugin that was created by iGetNet to aid Internet search. The plugin can be downloaded from www.igetnet.com website by clicking 'Try Demo' button.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


Originally detection of this plugin was added because the plugin's behaviour is malware-like: it is installed to user's system without confirmation and without showing a licence agreement, it can by itself download and run files on user's computer.

The GetNet plugin is distributed inside an installation package that is downloaded and activated on a computer when a user clicks certain area on IGetNet website. The installer drops the main plugin's file to a hard drive without showing any licence agreement or asking confimation from a user. The GetNet plugin's main file is dropped to Windows System folder as Winstart001.exe file and the special Registry key is created to make sure that the plugin's file is started during every Windows session:

[HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run]  "WinStart001.exe" = "%WinSysDir%\WinStart001.exe -b"  

where %WinSysDir% represents Windows System Directory.

The creator of the GetNet plugin provides uninstallation module for it. If you want to uninstall the plugin from your computer, you can download the uninstaller from here:

https://www.igetnet.com/downloads/uninstall_igetnet.asp





Description Details: Alexey Podrezov; F-Secure Corp.; April 25th, 2003


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More