Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
ASPNET_STATE.EXE has been seen to perform the following behavior:
- Drops known malicious software during execution
- Includes file creation code which could be used to test for interception by security products
- This process creates other processes on disk
- Executes a Process
- Enables an In Process Object/Server - Common with DLL Injections
- Adds a Registry Key (DELAY) to auto start Programs on system start up
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
ASPNET_STATE.EXE has been the subject of the following behavior:
- Created as a new Background Service on the machine
- Executed as a Process
- Created by processes which appear to be checking for interception by security products
- Created as a process on disk
- Deleted as a process from disk
- Executed from Temporary Folders
Country Of Origin
The filename ASPNET_STATE.EXE was first seen on Mar 13 2008 in the following geographical regions of the Prevx community:
- ITALY on Mar 13 2008
- The UNITED KINGDOM on Mar 28 2008
- SPAIN on Oct 21 2008
- HONG KONG on Jun 16 2009
- The UNITED STATES on Jul 14 2009
- The EUROPEAN UNION on Oct 20 2009
- VIET NAM on Oct 20 2009
File Name Aliases
ASPNET_STATE.EXE can also use the following file names:
- DRM3[n].TXT
- VRT7.TMP
- M8|ASPNET_STATE.EXE
- VRT5E45.TMP
- VRTE80D.TMP
- VRT820B.TMP
- CLIPSRV.EXE
- AOLTSMON.EXE
- PRESENTATIONFONTCACHE.EXE
- IEXPIORE.EXE
- MSCORSVW.EXE
- 6A.TMP
- 42.TMP
- 87.TM_
- M4|17106759.EXE
- 01C936B26AAAF67C_FDCD2T_EXE.PE
- 01C9347C8448BE9E_INDEX[1].PE
- ݢD
- 61062344.EXE
- 57204505.DAT
Filesizes
The following file size has been seen:
- 201,416 bytes
- 32,768 bytes
- 11,264 bytes
- 210,390 bytes
- 13,312 bytes
- 14,336 bytes
- 12,288 bytes
File Type
The filename ASPNET_STATE.EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name ASPNET_STATE.EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
- Creates c:\windows\system32\sxmg4.dll
- Deletes c:\windows\system32\lt.res
- Creates c:\windows\system32\sft.res
- Deletes c:\9.tm
Website Activity
One or more files with the name ASPNET_STATE.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1072 Port:16
- Port 80 IP:79.135.167.18
- Port 80 IP:91.203.93.49
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.