nethtsrv.exe

amisrv

The application nethtsrv.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Network HTTP Support Service”. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Product:
amisrv

Version:
1.2.0.5

MD5:
43e4e470a738801c618a36fc8ca62975

SHA-1:
472e4ca980bf0c5f862fd20ad759046d63be1c35

SHA-256:
fc7c209837286e8eff33c395ccf98b1eb5b2114eb5331e7d3b10157e25784f6c

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 5:30:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Netfilter.2
6561816

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.212.228

avast!
Win32:Amonetize-HF [PUP]
150101-1

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.15227

Bitdefender
Gen:Variant.Adware.Netfilter.2
1.0.20.290

Emsisoft Anti-Malware
Gen:Variant.Adware.Netfilter
9.0.0.4799

ESET NOD32
Win32/Amonetize.AZ potentially unwanted (variant)
9.11246

F-Secure
Gen:Variant.Adware.Netfilter.2
5.13.68

G Data
Gen:Variant.Adware.Netfilter
15.2.25

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2421

MicroWorld eScan
Gen:Variant.Adware.Netfilter.2
16.0.0.174

Norman
Gen:Variant.Adware.Netfilter.2
03.12.2014 13:20:04

Panda Antivirus
Generic Suspicious
15.02.27.09

Reason Heuristics
Threat.Win.Reputation.IMP
15.2.27.21

Sophos
PUA 'Amonetize'
5.11

VIPRE Antivirus
Threat.4785227
37588

File size:
330.5 KB (338,432 bytes)

Product version:
1.2.0.5

Copyright:
(c) 2012-2014, All rights reserved.

Original file name:
amisrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Windows\System32\nethtsrv.exe

File PE Metadata
Compilation timestamp:
2/16/2015 4:06:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
6144:NV+LybYwPXBkzrF2SeMhiz0/2C9Aa7GwI:NV+LykwPX+zrFPeMhizxC92wI

Entry address:
0x1EF35

Entry point:
E8, B3, CB, 00, 00, E9, 95, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A8, F7, 44, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A8, F7, 44, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.4341

Code size:
262.5 KB (268,800 bytes)

Service
Display name:
Network HTTP Support Service

Service name:
NetHttpService

Description:
This service sends network activity notifications to user mode processes. If this service is disabled, any other services that explicitly depend on this service will fail to operate properly.

Type:
Win32OwnProcess


Remove nethtsrv.exe - Powered by Reason Core Security