NetScope

NetScope is a potentially dangerous tool that scans a network continuously and seds email when a PC on the network is turned on or off. It can be used to run a program on the remote PC.

General information:

Malware Name: NetScope
Malware Type: Potentially Dangerous Tool
Company Name: Andrew V. Vladimirov
Company URL: http://amosoft.com.ru/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Andrew V. Vladimirov provides you the software NetScope that scans a network continuously, and checks when somebody switches a PC on. NetScope then sends an e-mail message to you or to your GSM SMS e-mail. When someone turns a PC off, NetScope also sends a message to you. NetScope also can play sound or run any program.

Spyware Description:

NetScope is a potentially dangerous tool that scans a network continuously and seds email when a PC on the network is turned on or off. It can be used to run a program on the remote PC.

Characteristics/Symptoms:

    -> It can be used to control a PC remotely -> Can be used to run any program on the remote PC

Additional information might be found here:

google Search at Google for NetScope
bing Search at Bing for NetScope
yahoo Search at Yahoo for NetScope

Processes Running:

NetScope.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\All Users\Start Menu\Programs\NetScope\Restore NetScope at the server.lnk 1581 Shortcut
C:\Program Files\NetScope\5QUERY.ICO 766 Icon
C:\Program Files\NetScope\netscopeHelp.htm 7421 HTM File

Folder information Created after Installation:

Folder Location

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Andrew V. Vladimirov\Applications\NetScope\MainForm.gActive_Columns Item0_DropDownRows
HKEY_LOCAL_MACHINE \SOFTWARE\Andrew V. Vladimirov\Applications\NetScope\MainForm.gActive_Columns Item0_Expanded
HKEY_LOCAL_MACHINE \SOFTWARE\Andrew V. Vladimirov\Applications\NetScope\MainForm.gActive_Columns Item0_FontColor