Should I block it?
90% of PCs block this file from running.
Possible reason:
Multiple malware detections
Relationships
Parent processes
Related files
netcut.exe
Arcai.com's NetCut by Arcai.com
Version: | 214 |
MD5: | 1cea2c2c9658d84a8e5e1207e1780e8c |
SHA1: | dd424cc0f586c745b6c5a3b1769a3d74d162cf87 |
SHA256: | 56d3226d9712699228adde1be57cede1fd941e06f9d6e68cc8a61431da3cdc3a |
Warning 3 antivirus scanners has detected malware.
Overview
netcut.exe is malware that executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent
aips.exe (AIPS Application by Arcai.com). This is typically installed with the program NetCut 2.1.4 published by arcai.com.
Details
File name: | netcut.exe |
Publisher: | Arcai.com |
Product name: | Arcai.com's NetCut |
Description: | NetCut Arp Spoof Application |
Typical file path: | C:\Program Files\netcut\netcut.exe |
File version: | 214 |
Size: | 876 KB (897,024 bytes) |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
.NET CLR: | No |
More details
Programs
The following program will install this file
“Discover who is on your network instantly. (IP/Device name/MAC address). Works in office LAN, school LAN or even Iphone/Xbox/Wii/PS3andriod/andriod network Find/export all MAC address in your network in seconds Turn off & on network on any device , computer/phone/xbox/wii/Router/switcher in your LAN. Protect user from ARP SPOOF attacks Change MAC address on any adapter. Clone MAC address from any device of your network to your own adapt...”
Network connections
[UDP] listens on port 1047
[UDP] listens on port 50830
[UDP] listens on port 60701
[UDP] listens on port 62384
Malware detections
Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Dr.Web |
8.13.8.10 |
Tool.Arp.9 |
ESET NOD32 |
7.9272 |
a variant of Win32/NetTool.Netcut.A |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0901 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.03261659% | |
Kernel CPU: | 0.02011088% | |
User CPU: | 0.01250571% | |
Kernel CPU time: | 7,999 ms/min | |
Context switches: | 1,066/sec | |
Memory |
Private memory: | 38.74 MB | |
Private (maximum): | 49.08 MB | |
Private (minimum): | 13.11 MB | |
Non-paged memory: | 38.74 MB | |
Virtual memory: | 153.33 MB | |
Virtual memory (peak): | 161.77 MB | |
Working set: | 47.62 MB | |
Working set (peak): | 49.16 MB | |
Page faults: | 16,800/min | |
Resource allocations |
Threads: | 13 | |
Handles: | 369 | |
GUI GDI count: | 113 | |
GUI GDI peak: | 124 | |
GUI USER count: | 89 | |
GUI USER peak: | 98 | |
Process properties
Integrety level: | System |
Platform: | 32-bit |
Command line: | "C:\Program Files\netcut\netcut.exe" |
Owner: | SYSTEM |
Parent processes: |
|
Threads
Averages
netcut.exe (main module) |
Total CPU: | 0.08901981% | |
Kernel CPU: | 0.03537310% | |
User CPU: | 0.05364672% | |
CPU cycles: | 8,595,680/sec | |
Context switches: | 127/sec | |
Memory: | 892 KB | |
actskn43.ocx (ActiveSkin Module) |
Total CPU: | 0.00386304% | |
Kernel CPU: | 0.00337876% | |
User CPU: | 0.00048428% | |
CPU cycles: | 1,261,748/sec | |
Context switches: | 89/sec | |
Memory: | 384 KB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
50.00% |
|
Microsoft Windows XP |
25.00% |
|
Windows Seven Black Edition |
25.00% |
|
Distribution by country
Egypt installs about 75.00% of Arcai.com's NetCut.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
66.67% |
|
Samsung |
33.33% |
|