Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
76270564.SVD has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- This process creates other processes on disk
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- This Process Deletes Other Processes From Disk
- The Process is polymorphic and can change its structure
- Registers a Dynamic Link Library File
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Disables safe mode on your PC
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
76270564.SVD has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Created by processes which appear to be checking for interception by security products
- Enabled as a COM Object/Server on the Local Machine
- Changes to the file command map within the registry
- Terminated as a Process
Country Of Origin
The filename 76270564.SVD was first seen on May 3 2007 in the following geographical regions of the Webroot community:
- Europe on May 3 2007
- Romania on Jun 29 2007
- The United States on Sep 28 2007
- The United Kingdom on Jan 5 2011
- Turkey on May 22 2012
File Name Aliases
76270564.SVD can also use the following file names:
- ACROBATINFO.EXE
- ACRORD32.EXE
- EF5M1012.BXE
- E_FAMTBOP.EXE
- DTC550MON.EXE
- CAPABILITYMANAGER.EXE
- IGFXSRVC.EXE
- E_FAMTAIP.EXE
- E_FARNAIP.EXE
- SAGENT4.EXE
- E_FBSRAIP.EXE
- E_FAMTBKP.EXE
- E_FARNBKP.EXE
- ACRORD32INFO.EXE
- ????????.RBF
Filesizes
The following file size has been seen:
- 305,664 bytes
- 81,459 bytes
- 14,456 bytes
- 90,112 bytes
File Type
The filename 76270564.SVD is used by multiple object types including executable programs,objects.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.