Associated Malware Groups
The filename is associated with the malware group:
File Behavior
FPH.EXE has been seen to perform the following behavior:
- The Process is polymorphic and can change its structure
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Creation and Registers a Browser Helper Object in Internet Explorer
- Enables a COM Object/Server on the Local Machine
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Registers a Dynamic Link Library File
- Enables an In Process Object/Server - Common with DLL Injections
FPH.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Enabled as a COM Object/Server on the Local Machine
- Executed as a Process
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename FPH.EXE was first seen on Oct 13 2007 in the following geographical regions of the Webroot community:
- Korea, Republic of on Oct 13 2007
- India on Oct 13 2007
- Spain on Nov 27 2007
- Turkey on May 16 2012
Filesizes
The following file size has been seen:
- 176,128 bytes
- 192,512 bytes
- 180,224 bytes
- 135,251 bytes
File Type
The filename FPH.EXE refers to many versions of an executable program.
File Activity
One or more files with the name FPH.EXE creates, deletes, copies or moves the following files and folders:
- Copies filec:\windows\system32\f_rc09.dll to c:\windows\system32\f_rc09.dll
- Copies filec:\windows\system32\f_pbrc09.dll to c:\windows\system32\f_pbrc09.dll
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.