Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malicious Software
- Malware Dropper
File Behavior
MSN.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Adds a Registry Key (DXCOM) to auto start Programs on system start up
- Modifies System Runtime Policies to limit system usability
- Writes to another Process's Virtual Memory (Process Hijacking)
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Executes a Process
- Creates new folders on the system
- Copies files
- Injects code into other processes
- Adds a Web Site Domain in the Internet Explorer Trusted Zone reducing its security protection
- Can communicate with other computer systems using HTTP protocols
- Uses a Registered MAPI
- Reads your outlook address book
- Modifies of the style sheet within Windows
- Registers a Dynamic Link Library File
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Deletes Links in the Start Menu
- Adds a Link in the Start Menu
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Performs DNS look ups to resolve URL IP addresses
- This Process is a file infector which modifies program files to include a copy of the infection
- Enables an In Process Object/Server - Common with DLL Injections
- Reads email address and phone book details
- Includes file creation code which could be used to test for interception by security products
- Runs Javascript code
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
MSN.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Added as a Registry Key (DXCOM) to auto start Programs on system start up
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Executed by Internet Explorer
- Copied to multiple locations on the system
- Registered as a Dynamic Link Library File
- Terminated as a Process
Country Of Origin
The filename MSN.EXE was first seen on Jun 20 2007 in the following geographical regions of the Webroot community:
- The United States on Jun 20 2007
- Canada on Jun 20 2007
- Uruguay on Aug 28 2009
- Spain on Nov 19 2009
- The United Kingdom on Nov 19 2009
- Tunisia on Jul 24 2010
- South Africa on Oct 18 2010
File Name Aliases
MSN.EXE can also use the following file names:
- ACTIVISION-CRACK.EXE
- BRS-CRACK.EXE
- BREAKPOINT SOFTWARE-CRACK.EXE
- ADOBE-CRACK.EXE
- AESCRYPT-CRACK.EXE
- COMMON FILES-CRACK.EXE
- CONDUIT-CRACK.EXE
- CPUID-CRACK.EXE
- DAEMON TOOLS LITE-CRACK.EXE
- DEEP SILVER-CRACK.EXE
- DISNEY INTERACTIVE STUDIOS-CRACK.EXE
- DVD MAKER-CRACK.EXE
- ELECTRIC RAIN-CRACK.EXE
- ADOBS-CRACK.EXE
- ELECTRONIC ARTS-CRACK.EXE
- ESET-CRACK.EXE
- FICHIERS COMMUNS-CRACK.EXE
- FIDDLER2-CRACK.EXE
- FINAL ARES COMPLETE EDITION-CRACK.EXE
- FROSTWIRE-CRACK.EXE
- FUJITSU SIEMENS COMPUTERS-CRACK.EXE
- GERMAN TRUCK SIMULATOR-CRACK.EXE
- GLOBE7-CRACK.EXE
- GOOGLE-CRACK.EXE
- HACKER EVOLUTION UNTOLD-CRACK.EXE
- HOTSPOT SHIELD-CRACK.EXE
- HTML HELP WORKSHOP-CRACK.EXE
- IIS-CRACK.EXE
- IMESH APPLICATIONS-CRACK.EXE
- IMMONITOR-CRACK.EXE
- INDEX.DAT ANALYZER-CRACK.EXE
- INSTALLSHIELD INSTALLATION INFORMATION-CRACK.EXE
- INTERNET DOWNLOAD MANAGER-CRACK.EXE
- INTERNET EXPLORER-CRACK.EXE
- IZYSOFT-CRACK.EXE
- JAVA-CRACK.EXE
- JDOWNLOADER-CRACK.EXE
- KONAMI-CRACK.EXE
- LIVEBRUSH-CRACK.EXE
- LOCKERZ_RESTOCK-CRACK.EXE
- MAGICISO-CRACK.EXE
- MAKAYAMA INTERACTIVE-CRACK.EXE
- MASS EFFECT-CRACK.EXE
- MAXTV-CRACK.EXE
- AGEIA TECHNOLOGIES-CRACK.EXE
- MOZILLA FIREFOX-CRACK.EXE
- MSBUILD-CRACK.EXE
- MYSQL-CRACK.EXE
- NEOSMART TECHNOLOGIES-CRACK.EXE
- NEOTRACEPRO-CRACK.EXE
- NMAP-CRACK.EXE
- NO-IP-CRACK.EXE
- NOGOMI.COM-CRACK.EXE
- NVIDIA CORPORATION-CRACK.EXE
- OMEMO-CRACK.EXE
- OPENAL-CRACK.EXE
- OPENTYPE TOOLS-CRACK.EXE
- OPHCRACK-CRACK.EXE
- PAQTOOL-CRACK.EXE
- PHPDESIGNER-CRACK.EXE
- PIXOLOGIC-CRACK.EXE
- PREVX-CRACK.EXE
- PUBLICATION WEB-CRACK.EXE
- QUICKTIME-CRACK.EXE
- REAL-CRACK.EXE
- REFERENCE ASSEMBLIES-CRACK.EXE
- RESOURCE TUNER-CRACK.EXE
- ROCKSTAR GAMES-CRACK.EXE
- SAFARI-CRACK.EXE
- APPLE SOFTWARE UPDATE-CRACK.EXE
- BANDOO-CRACK.EXE
- SCREENSCORNER-CRACK.EXE
- SEGA CORPORATION-CRACK.EXE
- SERENESCREEN-CRACK.EXE
- SKYPE-CRACK.EXE
- SOURCETEC-CRACK.EXE
- SWF DECOMPILER PREMIUM-CRACK.EXE
- AUTODESK-CRACK.EXE
- BT ENGINE-CRACK.EXE
- CAIN-CRACK.EXE
- APPLICATION SOUND EMBEDDER-CRACK.EXE
- AUTOIT3-CRACK.EXE
- TEAMVIEWER-CRACK.EXE
- TENABLE-CRACK.EXE
- CAWS-CRACK.EXE
- CDCHECK-CRACK.EXE
- SYSTEM.EXE
- MSN[1].EXE
- LSASS.EXE
- DCIM.EXE
- MISC.EXE
- SERVER.EXE
- 92719735.B
- 4SHARED-CRACK.EXE
- 17360874.EXE
Filesizes
The following file size has been seen:
- 20,437,198 bytes
- 327,168 bytes
- 123,051 bytes
- 88,576 bytes
- 649,888 bytes
- 148,811 bytes
- 90,112 bytes
File Type
The filename MSN.EXE refers to many versions of an executable program.
File Activity
One or more files with the name MSN.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\23556\actibrow.dl_
- Creates c:\23556\link.ico
- Creates c:\23556\nxframework.js
- Creates c:\23556\config.js
- Creates c:\23556\index.htm
- Creates c:\23556\bulkplugin.js
- Creates c:\23556\styles.css
- Creates c:\23556\bulk_exe.htm
- Creates c:\documents and settings\user\desktop\Ultimas Versiones.lnk
- Creates c:\documents and settings\user\start menu\Ultimas Versiones.lnk
- Creates c:\documents and settings\user\start menu\programs\23556\Uninstall.lnk
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.