Associated Malware Groups
The filename is associated with the malware group:
File Behavior
GPP3G.EXE has been seen to perform the following behavior:
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Disables the built in Windows File Protection System
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Injects code into other processes
- Creates new folders on the system
- Copies files
- Sets processes to start during user logon
- Found on infected systems and resists interrogation by security products
GPP3G.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Deleted as a process from disk
- Copied to multiple locations on the system
Country Of Origin
The filename GPP3G.EXE was first seen on Nov 21 2009 in the following geographical regions of the Prevx community:
- Italy on Nov 21 2009
- The United Kingdom on Nov 21 2009
- Argentina on Dec 10 2009
File Name Aliases
GPP3G.EXE can also use the following file names:
- P3[1].EXE
- 229.EXE
- 233.EXE
- 74608265.EXE
Filesizes
The following file size has been seen:
- 50,688 bytes
- 61,952 bytes
File Type
The filename GPP3G.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.