Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Information Stealer
- Worm
- Malware Downloader
File Behavior
ZCHMIB.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This process creates other processes on disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Checks for the use of debuggers
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
- Looks at the contents of the autoexec.bat file
- Opens browser pop ups
- Found on infected systems and resists interrogation by security products
- Can communicate with other computer systems using HTTP protocols
- Executes a Process
ZCHMIB.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Downloaded from covert web sites without the user knowing
- Executed as a Process
- Created as a new Background Service on the machine
Country Of Origin
The filename ZCHMIB.EXE was first seen on Mar 12 2009 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Mar 12 2009
- SPAIN on Mar 13 2009
- LITHUANIA on Mar 19 2009
File Name Aliases
ZCHMIB.EXE can also use the following file names:
- TEMPZCHMIB.EXE
- SAMPLE_SET 006 (nnn).EXE
- VS001953.WIN32.EXE
- SAMPLE_SET 015 (nnn).EXE
- ZCHMIB[n].EXE
- 31156316.EXE
- 73739539.EXE
- 18825268.SVD
Filesizes
The following file size has been seen:
- 403,456 bytes
- 484,595 bytes
- 484,591 bytes
- 484,573 bytes
- 334,434 bytes
- 334,450 bytes
File Type
The filename ZCHMIB.EXE refers to many versions of an executable program.
File Activity
One or more files with the name ZCHMIB.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\aut6.tmp
- Creates c:\docume~1\user\locals~1\temp\~allinfo.txt
- Deletes c:\docume~1\user\locals~1\temp\aut6.tmp
- Creates c:\docume~1\user\locals~1\temp\autA.tmp
- Creates c:\docume~1\user\locals~1\temp\curl.exe
- Deletes c:\docume~1\user\locals~1\temp\autA.tmp
- Opens/modifes c:\autoexec.bat
Website Activity
One or more files with the name ZCHMIB.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- 66 .90 .101 .177 / bots / control .php?action=getMessage&version=test|19
- Port 80 IP:66.90.101.177
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.