What is prnet.tmp?

prnet.tmp is usually located in the 'C:\WINDOWS\system32\' folder.

Vendor and version information [?]

prnet.tmp does not have any version or vendor information.

Digital signatures [?]

prnet.tmp is not signed.

Hashes [?]


What did other users do?

The poll result listed below shows what users chose to do with prnet.tmp. 92% have voted for removal. Based on votes from 37 users.

User vote results: There were 34 votes to remove and 3 votes to keep

Malware or legitimate?

ugeforever writes

1 thumb

Trojan.Virtumonde modifies the Windows Internet connection mechanism and display various pop-up advertisements.

File System Modifications

* The following file was created in the system:

1 %System%\prnet.tmp
35.499 bytes
MD5: 0x60DC1E87D0EB46F39F36AC2BA9106EA6
SHA-1: xC5E34F3DF87FDD34EB993237836E04BCEBE6B6E3
Trojan.Win32.VB [Ikarus]
packed with PE_Patch.PECompact [Kaspersky Lab]

* Note:
o %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Memory Modifications

* There were new processes created in the system:

prnet.tmp %System%\prnet.tmp 94.208 bytes

Registry Modifications

* The following Registry Key was created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prnet

* The newly created Registry Values are:
+ prnet = ""%System%\prnet.tmp""

so that prnet.tmp runs every time Windows starts
+ DisplayName = "Advertisement Service"
+ UninstallString = "%System%\prnet.tmp Uninstall"
o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
+ prnet = ""%System%\prnet.tmp""

so that prnet.tmp runs every time Windows starts

Other details

* To mark the presence in the system, the following Mutex object was created:

* The following ports were open in the system:

Port Protocol Process
1034 TCP prnet.tmp (%System%\prnet.tmp)
1036 UDP prnet.tmp (%System%\prnet.tmp)

* The following Internet Connection was established:

Server Name Server Port Connect as User Connection Password 80 (null) (null)

* The following GET requests were made:
o index.html
o index.jpg

# 5 May 2009, 8:55

