Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Malware Downloader
- Malicious Software
- Worm
File Behavior
DLD.EXE has been seen to perform the following behavior:
- Executes a Process
- Registers a Dynamic Link Library File
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Can communicate with other computer systems using HTTP protocols
- Adds a Registry Key (RUN) to auto start Programs on system start up
- The Process is packed and/or encrypted using a software packing process
- Adds products to the system registry
- Creates system tray popups, messages, errors and security warnings
- Uses backdoor interfaces to certain security applications
- Includes file creation code which could be used to test for interception by security products
- Uses DNS to retrieve the IP address for web sites
DLD.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Registered as a Dynamic Link Library File
- Executed by Internet Explorer
- Changes to the file command map within the registry
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename DLD.EXE was first seen on Sep 19 2007 in the following geographical regions of the Webroot community:
- Spain on Sep 19 2007
- Denmark on Sep 19 2007
- Europe on Oct 21 2007
- Mexico on Jul 13 2008
- Canada on Jul 13 2008
- Vietnam on Sep 12 2008
- Thailand on Sep 12 2008
- The United States on May 2 2012
Filesizes
The following file size has been seen:
- 3,088 bytes
- 177,953 bytes
- 28,207 bytes
- 1,384,448 bytes
- 90,112 bytes
- 1,351,680 bytes
File Type
The filename DLD.EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name DLD.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\c080_appcompat.txt
- Creates c:\docume~1\user\locals~1\temp\1CD8C.dmp
- Opens/modifes c:\autoexec.bat
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.