Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
FFF.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Found on infected systems and resists interrogation by security products
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Can communicate with other computer systems using HTTP protocols
- Uses low level functions to hide itself from the user and from system/security processes
- Adds a Registry Key (RUNONCE) to auto start Programs on system start up
- Executes a Process
- This Process Deletes Other Processes From Disk
- Registers a Dynamic Link Library File
- Creates new folders on the system
- Copies files
- Injects code into other processes
- Creates a new Background Service on the machine
FFF.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry Key (RUNONCE) to auto start Programs on system start up
- Copied to multiple locations on the system
- This program is often downloaded from the web
Country Of Origin
The filename FFF.EXE was first seen on Aug 29 2007 in the following geographical regions of the Webroot community:
- The United States on Aug 29 2007
- Korea, Republic of on Oct 1 2007
- Spain on Oct 1 2007
- The United Kingdom on Dec 3 2007
- Canada on Mar 31 2009
- Germany on Aug 14 2009
- Portugal on Mar 17 2010
- Thailand on Feb 4 2012
File Name Aliases
FFF.EXE can also use the following file names:
- ZZEXE (nn).EXE
- AAAFFF.EXE
- ANTIVIR.EXE
- SETUP_1069.EXE
- SETUP_1098.EXE
- HOYOZEBO.EXE
- FF[n].EXE
- TEMPFFF.EXE
- WWW2.EXE
- SAMPLE_SET 005 (nnn).EXE
- NNSPO.EXE
- FF.EXE
- 01CA1D2BDDCCD6CE_FFF_EXE.PE
- 01CA1D7A62B3F27A_FFF_EXE.PE
- 32407234
- 92195674
- F1F1.EXE
- 71587287.EXE
Filesizes
The following file size has been seen:
- 24,576 bytes
- 168,960 bytes
- 81,920 bytes
- 26,016 bytes
- 98,012 bytes
- 200,704 bytes
- 343,148 bytes
File Type
The filename FFF.EXE is used by multiple object types including executable programs,objects.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.