Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Information Stealer
- Cloaked Malware
- Worm
- Malware Downloader
File Behavior
STEAM.EXE has been seen to perform the following behavior:
- This Process Deletes Other Processes From Disk
- Can communicate with other computer systems using HTTP protocols
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- This process creates other processes on disk
- Changes to the file command map within the registry
- Registers a Dynamic Link Library File
- Adds products to the system registry
- Can communicate with other computers using TCP protocols
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Creates a TCP port which listens and is available for communication initiated by other computers
- Creates system tray popups, messages, errors and security warnings
- The Process is packed and/or encrypted using a software packing process
- Uses rootkit techniques to conceal its presence, interrogation or removal
- This Process is a file infector which modifies program files to include a copy of the infection
- Injects code into other processes
- Executes Processes stored in Temporary Folders
STEAM.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Changes to the file command map within the registry
- Executed by Internet Explorer
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Copied to multiple locations on the system
- Created by processes which appear to be checking for interception by security products
- Executed from Temporary Folders
Country Of Origin
The filename STEAM.EXE was first seen on May 22 2007 in the following geographical regions of the Webroot community:
- Netherlands on May 22 2007
- Spain on Sep 15 2007
- Croatia on Sep 15 2007
- France on Oct 14 2007
- Italy on Oct 17 2007
- Vietnam on Oct 17 2007
- The United States on Mar 27 2008
- Mexico on Aug 4 2009
- Europe on Oct 19 2009
- Poland on Jun 12 2010
- The United Kingdom on Jun 12 2010
- Turkey on May 23 2012
File Name Aliases
STEAM.EXE can also use the following file names:
- HACKXXX4.EXE
- PASSSTEALERV3_2.EXE
- MIS ARCHIVOS RECIBIDOS.EXE
- SUSOFT.EXE
- MUSICA.EXE
- ACCESORIOS.EXE
- ARCHIVOS DE PROGRAMA.EXE
- ESCRITORIO.EXE
- ACCESSORIOS.EXE
- INICIO.EXE
- MENú INICIO.EXE
- MIS DOCUMENTOS.EXE
- SUA.EXE
- WHITECAP.EXE
- WINRAR.EXE
- ACCESIBILIDAD.EXE
- ENTRETENIMIENTO.EXE
- ARCHIVOS COMUNES.EXE
- SERVICIO.EXE
- SITIOS WEB DE MICROSOFT.EXE
- VíNCULOS.EXE
- XEROX LINKS.EXE
- PDFCREATOR.EXE
- PROGRAMAS.EXE
- HERRAMIENTAS DEL SISTEMA.EXE
- SOP.VENTAS.EXE
- NGEDOCIE5UPD.EXE
- TEMP.EXE
- SYSTEM32.EXE
- WINDOWS.EXE
- MODULE07.EXE
- MODULE08.EXE
- DOCS.EXE
- ELOG.EXE
- CHUMBIAS.EXE
- LIMEWIRE.EXE
- ANGéLICA PINEDA.EXE
- DCIM.EXE
- PERSONAL.EXE
- RESPALDO PC ARMADA.EXE
- MI MúSICA.EXE
- ANGéLICA.EXE
- DRIVERS.EXE
- WBEM.EXE
- RESPALDO TRABAJO ANGÉLICA PINEDA.EXE
- MANIFESTS.EXE
- POLICIES.EXE
- X86_MICROSOFT.TOOLS.VISUALCPLUSPLUS.RUNTIME-LIBRARIES.RESOURCES_6595B64144CCF1DF_6.0.0.0_ES-ES_FF50B8B9.EXE
- X86_MICROSOFT.TOOLS.VISUALCPLUSPLUS.RUNTIME-LIBRARIES_6595B64144CCF1DF_6.0.0.0_X-WW_FF9986D7.EXE
- X86_MICROSOFT.VC80.ATL_1FC8B3B9A1E18E3B_8.0.50727.42_X-WW_6E805841.EXE
- X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.42_X-WW_0DE06ACD.EXE
- X86_MICROSOFT.VC80.MFC_1FC8B3B9A1E18E3B_8.0.50727.42_X-WW_DEC6DDD2.EXE
- X86_MICROSOFT.VC80.MFCLOC_1FC8B3B9A1E18E3B_8.0.50727.42_X-WW_3415F6D0.EXE
- X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.0.0_X-WW_1382D70A.EXE
- X86_POLICY.1.0.MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_X-WW_4E8510AC.EXE
- X86_POLICY.5.1.MICROSOFT.WINDOWS.SYSTEMCOMPATIBLE_6595B64144CCF1DF_X-WW_A0111510.EXE
- X86_POLICY.5.2.MICROSOFT.WINDOWS.NETWORKING.DXMRTP_6595B64144CCF1DF_X-WW_362E60DD.EXE
- X86_POLICY.5.2.MICROSOFT.WINDOWS.NETWORKING.RTCDLL_6595B64144CCF1DF_X-WW_C7B7206F.EXE
- X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.2180_X-WW_A84F1FF9.EXE
- X86_POLICY.6.0.MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_X-WW_5DDAD775.EXE
- X86_POLICY.7.0.MICROSOFT.WINDOWS.CPLUSPLUSRUNTIME_6595B64144CCF1DF_X-WW_A317E4B3.EXE
- X86_POLICY.8.0.MICROSOFT.VC80.ATL_1FC8B3B9A1E18E3B_X-WW_5F0BBCFF.EXE
- X86_POLICY.8.0.MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_X-WW_77C24773.EXE
- X86_MICROSOFT.WINDOWS.CPLUSPLUSRUNTIME_6595B64144CCF1DF_7.0.0.0_X-WW_2726E76A.EXE
- X86_POLICY.8.0.MICROSOFT.VC80.MFC_1FC8B3B9A1E18E3B_X-WW_0F75C32E.EXE
- X86_POLICY.8.0.MICROSOFT.VC80.MFCLOC_1FC8B3B9A1E18E3B_X-WW_CAEEE150.EXE
- DATA.OCT
- WINUPGRO.EXE
- SERIAL.EXE
- CURSORXP.EXE
- KEY_GEN.EXE
- GROOVEMONITOR.EXE
- INSTALL.EXE
- KEY_GENERATOR.EXE
- GOOGLEUPDATE.EXE
- CRAC.EXE
- INSTALL_PATCH.EXE
- INSTALL(1).EXE
- SETUP(1).EXE
- INSTALL_CRACK.EXE
- KEYGEN(1).EXE
- PATCH(1).EXE
- MSNMSGR.EXE
- M3|KEY_GEN.EXE
- NMBGMONITOR.EXE
- RAMBOOSTER.EXE
- PATCH.EXE
- GOOGLETOOLBARNOTIFIER.EXE
- COMMUNICATOR.EXE
- TOSCDSPD.EXE
- STEAMNEW.EXE
- STEAMTMP.EXE
- STEAM.EXE.BAK
- PW5.EXE
- DOCUMENTS AND SETTIN
- 595614.RBF
- 00265692.EXE
Filesizes
The following file size has been seen:
- 1,271,032 bytes
- 638,976 bytes
- 1,170,224 bytes
- 130,048 bytes
- 1,320,272 bytes
- 1,451,480 bytes
- 892,928 bytes
- 38,912 bytes
- 1,165,312 bytes
File Type
The filename STEAM.EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name STEAM.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\Musica.ex
- Creates d:\Musica.ex
- Creates e:\Musica.ex
- Creates c:\documents and settings\user\start menu\programs\startup\Musica.ex
- Creates c:\documents and settings\user\my documents\Musica.ex
- Creates c:\documents and settings\user\escritorio\SuSoft.exe
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.