net1.exe

Wipe, Secret Disk, Prevent Restore, Safe Startup

Yury Saprykin

This is a self-extracting archive and installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Secret Disk Maintance’. The file has been seen being downloaded from privacyroot.com.
Publisher:
www.privacyroot.com  (signed by Yury Saprykin)

Product:
Wipe, Secret Disk, Prevent Restore, Safe Startup

Description:
Application Installer

Version:
2.03.0.0

MD5:
94eaa34ff06458a0cc25b8a0be30e2ad

SHA-1:
e993825dee2582dc946fed8023ac7aa8818c20bd

SHA-256:
7f9ee98f0128ef8c6e1a99c36a039137aacfb3e42bcbb684980755c0c7c7f731

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 7:43:31 AM UTC  (today)

File size:
530.1 KB (542,872 bytes)

Product version:
2.03.0.0

Copyright:
privacyroot.com 2002 - 2014

Original file name:
NET2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\net1-sede\net1.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/13/2014 1:00:00 AM

Valid to:
3/13/2017 12:59:59 AM

Subject:
CN=Yury Saprykin, O=Yury Saprykin, STREET=Prospekt Revolucii 25, L=Voronezh, S=VO, PostalCode=394000, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C71956DD75CB37084C7A30D3E4519F3E

File PE Metadata
Compilation timestamp:
9/14/2014 10:31:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Z2Av1hiw9DAp+jbAoW/LBKlA5hTN+j+jr:bk/LJlN+I

Entry address:
0x7A20E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
481 KB (492,544 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Secret Disk Maintance

Command:
"C:\Program Files\net1-sede\net1.exe" windowsstartup


The file net1.exe has been discovered within the following program.

Secret Disk  by PrivacyRoot.com
Publisher's description - “Secret Disk can create additional disk on your PC, which can be invisible and locked with a password within one second. You can make your private files and folders invisible and protected. You don't need to format your hard disk or make any changes to boot sector.”
privacyroot.com
About 2% of users remove it
 
Powered by Should I Remove It?

The file net1.exe has been seen being distributed by the following URL.

Scan net1.exe - Powered by Reason Core Security