Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
NODENABLE.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Checks for the use of debuggers
- Uses DNS to retrieve the IP address for web sites
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- Adds products to the system registry
- This process creates other processes on disk
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
NODENABLE.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Executed from Temporary Folders
- Registered as a Dynamic Link Library File
Country Of Origin
The filename NODENABLE.EXE was first seen on Aug 11 2008 in the following geographical regions of the Webroot community:
- Switzerland on Aug 11 2008
- Iran, Islamic Republic of on Aug 11 2008
- Europe on Aug 31 2008
- Belgium on Aug 31 2008
- Philippines on Sep 5 2008
- Spain on Sep 25 2008
- Vietnam on Sep 25 2008
File Name Aliases
NODENABLE.EXE can also use the following file names:
- NODENABLE .EXE
- NODENABLER.EXE
- CYBERMANIA.EXE
- SHAHED.EXE
- NOD_WAS_ENABLE.EXE
- 93837067.EXE
- 87126005.EXE
- 01987512.EXE
- 32236204.SVD
- 15817173.EXE
- 08383517.EXE
- 88749894.EXE
- 69478311.EXE
- 77915794.EXE
- 88567609.EXE
Filesizes
The following file size has been seen:
- 359,639 bytes
- 326,909 bytes
- 359,463 bytes
- 327,335 bytes
- 326,823 bytes
File Type
The filename NODENABLE.EXE refers to many versions of an executable program.
File Activity
One or more files with the name NODENABLE.EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
- Creates c:\docume~1\user\locals~1\temp\temp.txt
Network Activity
One or more files with the name NODENABLE.EXE performs the following network events:
- Pings: 216.239.59.147
- Pings: 89.202.149.47
- Pings: 221.231.139.131
- Pings: 61.155.8.147
- DNS Lookup216.239.59.147 www.google.com
- DNS Lookup89.202.149.47 u37.eset.com
- DNS Lookup221.231.139.131 www.nod321.com
- DNS Lookup61.155.8.147 www.nod32sky.com
Website Activity
One or more files with the name NODENABLE.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- www .nod32sky .com
- Remote server connection to u37 .eset .co
- Port 80 IP:89.202.149.47
- Port 80 IP:61.155.8.147
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.