Associated Malware Groups
The filename is associated with the malware group:
File Behavior
TYGNQDTY.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes Processes stored in Temporary Folders
- This process creates other processes on disk
- Executes a Process
- This Process Deletes Other Processes From Disk
- Registers a Dynamic Link Library File
- Creates new folders on the system
- Injects code into other processes
- Disables Access to the Task Manager built into Windows
- Disables Access to the Windows Registry Editior
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Disables the Notification Balloon for the Windows Security Center
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Adds products to the system registry
- Terminates Processes
- Can communicate with other computer systems using HTTP protocols
TYGNQDTY.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename TYGNQDTY.EXE was first seen on Nov 20 2009 in the following geographical regions of the Prevx community:
- India on Nov 20 2009
- Egypt on Nov 20 2009
- Brazil on Nov 21 2009
- Grenada on Nov 23 2009
- Hungary on Nov 23 2009
- The United Kingdom on Dec 11 2009
File Name Aliases
TYGNQDTY.EXE can also use the following file name:
- KGHEYAJ.EXE
- DJGTGUHVVF[1].HTM
- XWTCMAWTT[1].HTM
- UKVMUEY.EXE
- WYWKYP.EXE
- JHRBGJY.EXE
- BWGOO.EXE
- FLRSSTGU[1].HTM
- 73571218.EXE
Filesizes
The following file size has been seen:
- 194,698 bytes
- 191,064 bytes
- 198,006 bytes
- 196,446 bytes
- 274,270 bytes
File Type
The filename TYGNQDTY.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.