xpnetdiag.exe

Network Diagnostic for Windows XP

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable xpnetdiag.exe, “Network Diagnostic for Windows XP” has been detected as malware by 38 anti-virus scanners.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
Microsoft® Windows® Operating System

Description:
Network Diagnostic for Windows XP

Version:
5.1.2600.5512 (xpsp.080413-0852)

MD5:
8f2ccad40f70989ecf6100db2e25c483

SHA-1:
109cca9b411ec61eac4aca32e3644e973d636195

Scanner detections:
38 / 68

Status:
Malware

Analysis date:
2/7/2026 9:42:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Polip.A
-39

Agnitum Outpost
Win32.Polipos.A
7.1.1

AhnLab V3 Security
Win32/Polip
2016.01.27

Avira AntiVirus
W32/Polip.A
8.3.2.4

Arcabit
Win32.Polip.A
1.0.0.646

avast!
Win32:Polipos
2014.9-170315

AVG
Win32/Polipos
2018.0.2439

Baidu Antivirus
Virus.Win32.Polip.$a
4.0.3.17315

Bitdefender
Win32.Polip.A
1.0.20.370

Clam AntiVirus
Heuristics.W32.Polipos.A
0.98/21511

Comodo Security
P2PWorm.Win32.Polip.A
24021

Dr.Web
Win32.Polipos
9.0.1.074

Emsisoft Anti-Malware
Win32.Polip
8.17.03.15.08

ESET NOD32
Win32/Polip
11.12928

Fortinet FortiGate
W32/Polip.A
3/15/2017

F-Prot
W32/Polip.A
v6.4.7.1.166

F-Secure
Win32.Polip.A
11.2017-15-03_4

G Data
Win32.Polip
17.3.25

IKARUS anti.virus
Win32.Polip
t3scan.2.0.3.0

K7 AntiVirus
Virus
13.212.18540

Kaspersky
P2P-Worm.Win32.Polip
14.0.0.-1312

McAfee
W32/Polip
5600.6095

Microsoft Security Essentials
Virus:Win32/Polip.A
1.1.12400.0

MicroWorld eScan
Win32.Polip.A
18.0.0.222

NANO AntiVirus
Virus.Win32.Polip.fzoi
1.0.14.5380

nProtect
Virus/W32.Polip
16.01.26.01

Panda Antivirus
Generic Suspicious
17.03.15.08

Qihoo 360 Security
Win32/Trojan.020
1.0.0.1077

Quick Heal
W32.PoliPos
3.17.14.00

Rising Antivirus
PE:Win32.Polipos!270422 [F]
23.00.65.17313

Sophos
W32/Polipos-A
4.98

Total Defense
Win32/Polip.A
37.1.62.1

Trend Micro House Call
PE_POLIP.A
7.2.74

Trend Micro
PE_POLIP.A
10.465.15

Vba32 AntiVirus
Virus.Win32.Polip.A
3.12.26.4

VIPRE Antivirus
Virus.Polips!WB
46772

ViRobot
Win32.Polip.Gen.A[h]
2014.3.20.0

Zillya! Antivirus
Virus.Polip.Win32.1
2.0.0.2631

File size:
603 KB (617,472 bytes)

Product version:
5.1.2600.5512

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
xpnetdiag.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\network diagnostic\xpnetdiag.exe

File PE Metadata
Compilation timestamp:
4/14/2008 2:53:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x22B99

Entry point:
6A, 70, 68, 40, 8F, 00, 01, E8, FF, 03, 00, 00, 33, FF, 57, FF, 15, 50, 11, 00, 01, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 02, 5B, 53, FF, 15, EC, 16, 00, 01, 59, 83, 0D, 14, F8, 02, 01, FF, 83, 0D, 18, F8...
 
[+]

Entropy:
4.9659

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
236 KB (241,664 bytes)

Internet Explorer Extension
Name:
{e2e2dd38-d088-4134-82b7-f2ba38496583}


Remove xpnetdiag.exe - Powered by Reason Core Security