Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
WINJPMU.EXE has been seen to perform the following behavior:
- Disables the Notification Balloon for the Windows Security Center
- Disables Access to the Task Manager built into Windows
- Disables Access to the Windows Registry Editior
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Changes the Windows Security Center to stop Antivirus status alerts from being displayed
- Changes the Windows Security Senter to stop Firewall status alerts from being displayed
- Changes the Windows Security Center to stop Firewall override alerts from being displayed
- Changes the Windows Security Center to stop warnings from being displayed if automatic Windows Updates are not enabled
- Injects code into other processes
WINJPMU.EXE has been the subject of the following behavior:
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
Country Of Origin
The filename WINJPMU.EXE was first seen on Nov 17 2009 in the following geographical regions of the Prevx community:
- Vietnam on Nov 17 2009
- The United Kingdom on Nov 17 2009
Filesizes
The following file size has been seen:
- 32,768 bytes
- 151,040 bytes
File Type
The filename WINJPMU.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.