Associated Malware Groups
The filename is associated with the malware groups:
File Behavior
XWFST.SYS has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Found on infected systems and resists interrogation by security products
- Executes a Process
- Injects code into other processes
- This process creates other processes on disk
- Uses hidden browser windows to connect to web sites without telling you
- Opens browser pop ups
- Runs Javascript code
- Creates system tray popups, messages, errors and security warnings
XWFST.SYS has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename XWFST.SYS was first seen on Jun 26 2008 in the following geographical regions of the Webroot community:
- Denmark on Jun 26 2008
- The United States on Jun 26 2008
- Europe on Jun 27 2008
- South Africa on Jun 29 2008
- Canada on Nov 17 2009
- The United Kingdom on Nov 17 2009
File Name Aliases
XWFST.SYS can also use the following file names:
- XFST.SYS
- XWXFST.SYS
- CATCHME.TMP
- XWXFST.SYS.BAK
- 67829629.SYS
- 66341147.SVD
Filesizes
The following file size has been seen:
- 40,960 bytes
- 36,864 bytes
File Type
The filename XWFST.SYS refers to many versions of an executable program.
File Activity
One or more files with the name XWFST.SYS creates, deletes, copies or moves the following files and folders:
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\dnserrordiagoff_webOC[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\ErrorPageTemplate[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\7gddxlhz\errorPageStrings[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\httpErrorPagesScripts[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\background_gradient[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\info_48[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\bullet[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\4cvefhyb\down[1]
Website Activity
One or more files with the name XWFST.SYS interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1090 Port:19
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.