Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
76270564.SVD has been seen to perform the following behavior:
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- Executes a Process
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Registers a Dynamic Link Library File
- This Process is a file infector which modifies program files to include a copy of the infection
- Includes file creation code which could be used to test for interception by security products
- The Process is polymorphic and can change its structure
- The Process is packed and/or encrypted using a software packing process
- Makes outbound connections to other computers using NETBIOSOUT protocols
76270564.SVD has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Created by processes which appear to be checking for interception by security products
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Enabled as a COM Object/Server on the Local Machine
- Changes to the file command map within the registry
- Terminated as a Process
Country Of Origin
The filename 76270564.SVD was first seen on May 3 2007 in the following geographical regions of the Prevx community:
- Europe on May 3 2007
- Romania on Jun 29 2007
- The United States on Sep 28 2007
- China on Mar 15 2010
File Name Aliases
76270564.SVD can also use the following file names:
- ACROBATINFO.EXE
- ACRORD32.EXE
- EF5M1012.BXE
- E_FAMTBOP.EXE
- DTC550MON.EXE
- CAPABILITYMANAGER.EXE
- IGFXSRVC.EXE
- E_FAMTAIP.EXE
- E_FARNAIP.EXE
- SAGENT4.EXE
- E_FBSRAIP.EXE
- E_FAMTBKP.EXE
- E_FARNBKP.EXE
- ACRORD32INFO.EXE
- ACRORD32INFO.EXE.EXE
- ????????.RBF
Filesizes
The following file size has been seen:
- 99,259 bytes
- 41,984 bytes
- 305,664 bytes
- 81,459 bytes
- 14,456 bytes
File Type
The filename 76270564.SVD is used by multiple object types including objects,executable programs.
File Activity
One or more files with the name 76270564.SVD creates, deletes, copies or moves the following files and folders:
- create folder C:\WINDOWS\uninstall\
- Creates c:\windows\uninstall\rundl132.exe
- Creates c:\windows\Logo1_.exe
- Deletes c:\docume~1\user\locals~1\temp\$$aB.bat
- Creates c:\docume~1\user\locals~1\temp\$$aB.bat
- Creates c:\windows\RichDll.dll
- Creates c:\_desktop.ini
- Deletes c:\mbr\scan.exe
- Creates c:\mbr\scan.exe
- Moves c:\mbr\scan.exe to c:\mbr\scan.exe
- Deletes c:\program files\ati technologies\uninstallall\AtiCimUn.exe
- Creates c:\program files\ati technologies\uninstallall\AtiCimUn.exe
- Moves c:\program files\ati technologies\uninstallall\AtiCimUn.exe to c:\program files\ati technologies\uninstallall\AtiCimUn.exe
- Deletes c:\program files\intel\ncs2\wmiprov\ncs2prov.exe
- Creates c:\program files\intel\ncs2\wmiprov\ncs2prov.exe
- Moves c:\program files\intel\ncs2\wmiprov\ncs2prov.exe to c:\program files\intel\ncs2\wmiprov\ncs2prov.exe
- Deletes c:\program files\intel\ncs2\wmiprov\NCSDiag.exe
- Creates c:\program files\intel\ncs2\wmiprov\NCSDiag.exe
- Moves c:\program files\intel\ncs2\wmiprov\NCSDiag.exe to c:\program files\intel\ncs2\wmiprov\NCSDiag.exe
- Deletes c:\program files\msn\msncorefiles\install\msnsusii.exe
- Creates c:\program files\msn\msncorefiles\install\msnsusii.exe
- Moves c:\program files\msn\msncorefiles\install\msnsusii.exe to c:\program files\msn\msncorefiles\install\msnsusii.exe
- Deletes c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
- Creates c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
- Moves c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe to c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
- Deletes c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
- Creates c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
- Moves c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe to c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
- Deletes c:\program files\realtek\installshield\ChCfg.exe
- Creates c:\program files\realtek\installshield\ChCfg.exe
- Moves c:\program files\realtek\installshield\ChCfg.exe to c:\program files\realtek\installshield\ChCfg.exe
- Deletes c:\program files\realtek\installshield\RtlUpd.exe
- Creates c:\program files\realtek\installshield\RtlUpd.exe
- Moves c:\program files\realtek\installshield\RtlUpd.exe to c:\program files\realtek\installshield\RtlUpd.exe
- Deletes c:\program files\realtek\installshield\RtlUpd64.exe
- Creates c:\program files\realtek\installshield\RtlUpd64.exe
- Moves c:\program files\realtek\installshield\RtlUpd64.exe to c:\program files\realtek\installshield\RtlUpd64.exe
- Deletes c:\program files\windows live\installer\Dashboard.exe
- Creates c:\program files\windows live\installer\Dashboard.exe
- Moves c:\program files\windows live\installer\Dashboard.exe to c:\program files\windows live\installer\Dashboard.exe
- Deletes c:\program files\windows live\installer\WLSetupSvc.exe
- Creates c:\program files\windows live\installer\WLSetupSvc.exe
- Moves c:\program files\windows live\installer\WLSetupSvc.exe to c:\program files\windows live\installer\WLSetupSvc.exe
- Deletes c:\program files\winpcap\rpcapd.exe
- Creates c:\program files\winpcap\rpcapd.exe
- Moves c:\program files\winpcap\rpcapd.exe to c:\program files\winpcap\rpcapd.exe
- Deletes c:\program files\winpcap\Uninstall.exe
- Creates c:\program files\winpcap\Uninstall.exe
- Moves c:\program files\winpcap\Uninstall.exe to c:\program files\winpcap\Uninstall.exe
- Creates c:\docume~1\user\locals~1\temp\620d_appcompat.txt
Network Activity
One or more files with the name 76270564.SVD performs the following network events:
- DNS Lookup1.1.21.1 BECKY-890DC1AB
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.