Associated Malware Groups
The filename is associated with the malware group:
File Behavior
WEXE.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Modifies Windows Initialization And System Settings Used On Start up
- This process creates other processes on disk
- Executes a Process
- Found on infected systems and resists interrogation by security products
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This Process Deletes Other Processes From Disk
- Copies files
- Injects code into other processes
- Creates new folders on the system
- The Process is packed and/or encrypted using a software packing process
- Enables an In Process Object/Server - Common with DLL Injections
WEXE.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Executed from Temporary Folders
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Copied to multiple locations on the system
Country Of Origin
The filename WEXE.EXE was first seen on Jul 20 2007 in the following geographical regions of the Webroot community:
- The United States on Jul 20 2007
- Brazil on Aug 28 2008
- Canada on Dec 28 2009
- Portugal on Jan 1 2010
- Italy on Mar 19 2010
Filesizes
The following file size has been seen:
- 36,864 bytes
- 28,672 bytes
- 131,072 bytes
- 90,112 bytes
- 40,832 bytes
- 13,312 bytes
- 38,656 bytes
- 43,392 bytes
File Type
The filename WEXE.EXE is used by multiple object types including executable programs,objects.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.