Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
X3[n].EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Creates new folders in the file system
- Creates a new Background Service on the machine
- Uses DNS to retrieve the IP address for web sites
- Uses reverse DNS to retrieve the host names on IP addresses
- Uses your PC to connect to Chat rooms
- The Process is polymorphic and can change its structure
- Found on infected systems and resists interrogation by security products
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- The Process is packed and/or encrypted using a software packing process
X3[n].EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Executed as a Process
- Copied to multiple locations on the system
- Registered as a Dynamic Link Library File
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Created as a process on disk
Country Of Origin
The filename X3[n].EXE was first seen on Jun 22 2007 in the following geographical regions of the Webroot community:
- Spain on Jun 22 2007
- Pakistan on Jun 22 2007
- Taiwan on Aug 13 2008
- Portugal on Mar 21 2009
- Italy on Mar 21 2009
- Japan on Apr 4 2009
File Name Aliases
X3[n].EXE can also use the following file names:
- PIZK.EXE
- TZJAI.EXE
- WINHOST.EXE
- GRCNZX.EXE
- JTOUMKY.EXE
- PWYFOTOZ.EXE
- QBORBQ.EXE
- TWWYIILI.EXE
- HEHNTPZ.EXE
- XHUSPZSC.EXE
- KQSKMTE.EXE
- NXZKGEFV.EXE
- WQOROQZZ.EXE
- SUSPICIOUS FILES/SYSTEM32/ADMIN/LSASSER.EX_
- SUSPICIOUS FILES/X3.EXE
- MCVSVR.EXE
- LSASSER.EXE
- X3[1].EXE
- X3[2].EXE
- 3.EXE
- X3.EXE
- ½ØÍ¼²¢±£´ÆÎªJPG¸Ñʽ.EXE
- 08L3JPG3c0f09L5.EXE
- 09805503.CO
- 12852148.CO
Filesizes
The following file size has been seen:
- 159,794 bytes
- 39,424 bytes
- 29,696 bytes
- 51,712 bytes
- 214,528 bytes
File Type
The filename X3[n].EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name X3[n].EXE creates, deletes, copies or moves the following files and folders:
- create folder C:\WINDOWS\system32\admin
- Deletes c:\documents and settings\user\desktop\a.exe
- Deletes c:\documents and settings\user\desktop\b.exe
- Deletes c:\documents and settings\user\desktop\e.exe
- Deletes c:\documents and settings\user\desktop\g
- Deletes c:\documents and settings\user\desktop\k
- Deletes c:\windows\system32\admin\lsasser.exe
- Creates c:\windows\system32\admin\desktop.sys
- Creates c:\windows\system32\admin\explorer.sys
- Creates c:\windows\system32\admin\user32.dll
- Creates c:\windows\system32\admin\gdi32.dll
- Creates c:\windows\system32\admin\win.ini
- Deletes c:\program files\symantec\liveupdate\LUALL.EXE
- Deletes c:\program files\mcafee.com\agent\mcupdate.exe
- Deletes c:\program files\grisoft\avg free\avginet.exe
Network Activity
One or more files with the name X3[n].EXE performs the following network events:
- DNS Lookup61.136.69.197 dns2.buztest.com
- DNS get hostDC32-KAO348Y1 192.168.0.8
Website Activity
One or more files with the name X3[n].EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:61.136.69.197:81 Port:14
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.