Associated Malware Groups
The filename is associated with the malware groups:
- Fraudulent Security Program
- System Back Door
File Behavior
.TT7.TMP has been seen to perform the following behavior:
- Adds products to the system registry
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Executes a Process
- This Process Deletes Other Processes From Disk
- Registers a Dynamic Link Library File
- This Process is a file infector which modifies program files to include a copy of the infection
- Opens browser pop ups
- Writes to another Process's Virtual Memory (Process Hijacking)
- Found on infected systems and resists interrogation by security products
- The Process is packed and/or encrypted using a software packing process
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
.TT7.TMP has been the subject of the following behavior:
- Executed from Temporary Folders
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Copied to multiple locations on the system
- Created as a new Background Service on the machine
Country Of Origin
The filename .TT7.TMP was first seen on May 20 2008 in the following geographical regions of the Webroot community:
- The United States on May 20 2008
- Brazil on Aug 25 2008
Filesizes
The following file size has been seen:
- 2,031,832 bytes
- 23,552 bytes
- 3,367,760 bytes
File Type
The filename .TT7.TMP refers to many versions of an executable program.
File Activity
One or more files with the name .TT7.TMP creates, deletes, copies or moves the following files and folders:
- create folder C:\Program Files\AXPFixe
- Deletes c:\docume~1\user\locals~1\temp\nsu8.tmp
- Creates c:\docume~1\user\locals~1\temp\nszA.tmp
- Deletes c:\docume~1\user\locals~1\temp\nszC.tmp
- Creates c:\docume~1\user\locals~1\temp\nszc.tmp\update.ini
- Creates c:\docume~1\user\locals~1\temp\nszc.tmp\lastpage.ini
- Creates c:\docume~1\user\locals~1\temp\nszc.tmp\Mutex.dll
- Creates c:\documents and settings\all users\start menu\programs\advanced xp fixer\Uninstall.lnk
- Creates c:\documents and settings\all users\start menu\programs\advanced xp fixer\Advanced XP Fixer.lnk
- Creates c:\documents and settings\all users\start menu\programs\Advanced XP Fixer.lnk
- Creates c:\documents and settings\all users\start menu\programs\advanced xp fixer\License Agreement.lnk
- Creates c:\documents and settings\user\application data\microsoft\internet explorer\quick launch\AXPFixer.lnk
- Creates c:\documents and settings\all users\desktop\AXPFixer.lnk
- Creates c:\documents and settings\all users\start menu\programs\advanced xp fixer\Register Advanced XP Fixer.lnk
- Creates c:\documents and settings\all users\start menu\programs\advanced xp fixer\How to Register Advanced XP Fixer.lnk
- Creates c:\program files\axpfixer\AXPFixer.exe
- Creates c:\program files\axpfixer\database.dat
- Creates c:\program files\axpfixer\AXPFixerSkin.dll
- Creates c:\program files\axpfixer\msvcp71.dll
- Creates c:\program files\axpfixer\MFC71.dll
- Creates c:\program files\axpfixer\MFC71ENU.DLL
- Creates c:\program files\axpfixer\msvcr71.dll
- Creates c:\program files\axpfixer\license.txt
- Creates c:\docume~1\user\locals~1\temp\pin.vbs
- Deletes c:\docume~1\user\locals~1\temp\pin.vbs
- Creates c:\program files\axpfixer\Uninstall.exe
- Creates c:\docume~1\user\locals~1\temp\nszc.tmp\KillSelf.dll
- Deletes c:\docume~1\user\locals~1\temp\nszc.tmp\KillSelf.dll
- Deletes c:\docume~1\user\locals~1\temp\nszc.tmp\lastpage.ini
- Deletes c:\docume~1\user\locals~1\temp\nszc.tmp\Mutex.dll
- Deletes c:\docume~1\user\locals~1\temp\nszc.tmp\update.ini
- Deletes c:\documents and settings\user\local settings\temp\pkgp.bat
- Creates c:\docume~1\user\locals~1\temp\compress.dat
- Deletes c:\docume~1\user\locals~1\temp\compress.dat
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.