nethtsrv.exe

amisrv

The application nethtsrv.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Network HTTP Support Service”. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Product:
amisrv

Version:
1.2.0.5

MD5:
b7894c017e1115535e9c78fc358aac29

SHA-1:
6681e1a986bca9dd759f5bc10b95ee008ca3e52f

SHA-256:
9350ceefc35c603b4e628c8e331f5083aa9f342f0a43f9e8cfbc502213a219ad

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
5/7/2024 3:52:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Netfilter.2
5533056

AhnLab V3 Security
PUP/Win32.Amonetize
2015.05.22

Avira AntiVirus
ADWARE/Amonetize.Gen7
8.3.1.6

avast!
Win32:Amonetize-HF [PUP]
150521-0

AVG
Adware BundleApp.EFA
2014.0.4311

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.15521

Bitdefender
Gen:Variant.Adware.Netfilter.2
1.0.20.705

Comodo Security
Application.Win32.Amonetize.DAX
22203

Emsisoft Anti-Malware
Gen:Variant.Adware.Netfilter
10.0.0.5366

ESET NOD32
Win32/Amonetize.AZ potentially unwanted (variant)
9.11665

Fortinet FortiGate
Riskware/Amonetize
5/21/2015

F-Secure
Gen:Variant.Adware.Netfilter
11.2015-21-05_5

G Data
Gen:Variant.Adware.Netfilter
15.5.25

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2005

Malwarebytes
PUP.Optional.Amonetize
v2015.05.21.11

MicroWorld eScan
Gen:Variant.Adware.Netfilter.2
16.0.0.423

Norman
Gen:Variant.Adware.Netfilter.2
03.12.2014 13:20:04

Panda Antivirus
Trj/Genetic.gen
15.05.21.11

Reason Heuristics
PUP.Amonitize.Meta
15.5.21.22

Sophos
PUA 'Amonetize'
5.14

SUPERAntiSpyware
Adware.NetFilter/Variant
9861

Trend Micro House Call
TROJ_GEN.R0C1H09EK15
7.2.141

VIPRE Antivirus
Threat.4785227
40432

File size:
331 KB (338,944 bytes)

Product version:
1.2.0.5

Copyright:
(c) 2012-2014, All rights reserved.

Original file name:
amisrv.exe

File type:
Executable application (Win32 EXE)

Language:
Ingilizce (Birlesik Krallik)

Common path:
C:\windows\syswow64\nethtsrv.exe

File PE Metadata
Compilation timestamp:
5/20/2015 1:45:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
6144:u5rehKx/M9GV/NCzRXK5VLLQFT2CKrT7gv:u56hKdM4V8zRXiVLLQgCKUv

Entry address:
0x1F265

Entry point:
E8, 58, CB, 00, 00, E9, 95, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A8, F7, 44, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A8, F7, 44, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
263 KB (269,312 bytes)

Service
Display name:
Network HTTP Support Service

Service name:
NetHttpService

Description:
This service sends network activity notifications to user mode processes. If this service is disabled, any other services that explicitly depend on this service will fail to operate properly.

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-website-us-west-2.amazonaws.com  (54.231.176.175:80)

Remove nethtsrv.exe - Powered by Reason Core Security