File Behavior
ADDT.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Disables the Notification Balloon for the Windows Security Center
- Disables the Windows Built in Firewall enabling rogue processes to access the internet without your knowledge or permission
- This process creates other processes on disk
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Disables the Windows Security Center Service
- Executes a Process
- This Process Deletes Other Processes From Disk
- Sends email using SMTP protocols
- Can communicate with other computer systems using HTTP protocols
- Registers a Dynamic Link Library File
- Creates a new Background Service on the machine
- Changes the Windows Security Center to stop Firewall override alerts from being displayed
- Changes the Windows Security Senter to stop Firewall status alerts from being displayed
ADDT.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Terminated as a Process
- Created as a new Background Service on the machine
- Registered as a Dynamic Link Library File
Country Of Origin
The filename ADDT.EXE was first seen on Nov 2 2009 in the following geographical region of the Prevx community:
- RUSSIAN FEDERATION on Nov 2 2009
File Name Aliases
ADDT.EXE can also use the following file names:
- ANUT.EXE
- SERVICES.EXE
- AN[1].EXE
Filesizes
This file has been seen with the following file size:
File Type
The filename ADDT.EXE refers to an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.