Associated Malware Groups
The filename is associated with the malware groups:
- Information Stealer
- System Back Door
- Cloaked Malware
File Behavior
MY_SERVER.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- This process creates other processes on disk
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Checks for the use of debuggers
- The Process is polymorphic and can change its structure
- Registers a Dynamic Link Library File
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- Adds products to the system registry
- Adds a Registry Key (DXCOM) to auto start Programs on system start up
- This Process Deletes Other Processes From Disk
MY_SERVER.EXE has been the subject of the following behavior:
- Executed as a Process
- The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Created by processes which appear to be checking for interception by security products
- Terminated as a Process
- Added as a Registry Key (DXCOM) to auto start Programs on system start up
- Deleted as a process from disk
- Executed by Internet Explorer
Country Of Origin
The filename MY_SERVER.EXE was first seen on Jun 15 2007 in the following geographical regions of the Webroot community:
- on Jun 15 2007
- The United Kingdom on Jun 15 2007
- Spain on Jun 25 2007
- Canada on Jun 25 2007
- Turkey on Jul 30 2007
- Uruguay on Mar 31 2008
- Bulgaria on Dec 10 2008
- Austria on Feb 6 2011
File Name Aliases
MY_SERVER.EXE can also use the following file names:
- SERVER.EXE
- TEMP.EXE
- INSTALLDUMP.EXE
- 45467684.EXE
- 57588863.EXE
- 38069155.EXE
- 46797163.SVD
- 05078604.SVD
- 21643608.SVD
- 03490732.EX_
- 11939847.EXE
- 14793135.DAT
Filesizes
The following file size has been seen:
- 1,339,868 bytes
- 1,241,535 bytes
- 1,488,444 bytes
- 915,907 bytes
- 287,143 bytes
- 73,159 bytes
- 276,417 bytes
File Type
The filename MY_SERVER.EXE refers to many versions of an executable program.
File Activity
One or more files with the name MY_SERVER.EXE creates, deletes, copies or moves the following files and folders:
- create folder C:\WINDOWS\system32\
- Deletes c:\documents and settings\user\application data\tXmpX
- Creates c:\windows\system32\My_Server.exe
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.