Threat behavior
TrojanDownloader:Win32/Monnet is bundled with third-party software that includes Network Monitor, a tool used to monitor network traffic. Win32/Monnet may contact a remote Web server, register its installation, and await further commands.
Installation
Win32/Monnet may create the following files on an affected machine:
%ProgramFiles%\network monitor
%AppData%\netmon
%SystemDrive%\Documents and Settings\LocalService\Application Data\netmon
%programfiles%\network monitor\netmon.exe
%windir%\uninstall_nmon.vbs
During installation, the registry is modified to include the following keys within the hive HKEY_LOCAL_MACHINE:
..\SYSTEM\CurrentControlSet\Services\Network Monitor
..\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE}
Win32/Monnet may include an uninstaller, written in VBScript, as 'uninstall_nmon.vbs'. This uninstaller is linked with an entry created in 'Add or Remove Programs' named "Network Monitor".
Additional Information
This threat has been observed in the wild consistently in connection with Adware:Win32/CMDService.
Prevention