Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
WDFMGR.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Executes a Process
- This Process Deletes Other Processes From Disk
- Can communicate with other computer systems using HTTP protocols
- Registers a Dynamic Link Library File
- The Process is polymorphic and can change its structure
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Disables the built in Windows File Protection System
- Can communicate with other computers using TCP protocols
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes Processes stored in Temporary Folders
- Checks for the use of debuggers
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Includes file creation code which could be used to test for interception by security products
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Uses DNS to retrieve the IP address for web sites
- Visits web sites on your PC without you knowing
WDFMGR.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed from Temporary Folders
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Created as a new Background Service on the machine
- Copied to multiple locations on the system
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename WDFMGR.EXE was first seen on May 3 2007 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on May 3 2007
- The UNITED KINGDOM on May 3 2007
- VIET NAM on Dec 22 2008
- GREAT BRITAIN on Dec 22 2008
- The UNITED STATES on Nov 20 2009
File Name Aliases
WDFMGR.EXE can also use the following file names:
- ERASEME_86363.EXE
- WWW.Z058_JPG-MSN.COM
- ERASEME_40262.EXE
- ERASEME_87436.EXE
- ERASEME_75153.EXE
- ERASEME_16386.EXE
- ERASEME_18243.EXE
- WDFMGR.0XE
- ERASEME_01036.EXE
- ERASEME_57180.EXE
- ERASEME_78723.EXE
- ERASEME_58605.EXE
- SET53.TMP
- III.EXE
- WMCCDS.EXE
- WMCCFG.EXE
- UWDF.EXE
- DPLRNK~1.EXE
- DOCUMENTS AND SETTIN
Filesizes
The following file size has been seen:
- 541,696 bytes
- 39,191 bytes
- 19,996 bytes
- 8,704 bytes
File Type
The filename WDFMGR.EXE is used by multiple object types including executable programs,objects.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.