Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Worm
- Malware Downloader
- Malicious Software
File Behavior
48552331.EXE has been seen to perform the following behavior:
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- This process creates other processes on disk
- This Process is a file infector which modifies program files to include a copy of the infection
- The Process is polymorphic and can change its structure
- Can Send email using SMTP protocols
- This Process sends MIME Email
- Creates a hidden window which can be used to run other programs without your knowledge
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Registers a Dynamic Link Library File
48552331.EXE has been the subject of the following behavior:
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Executed as a Process
- Terminated as a Process
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename 48552331.EXE was first seen on May 3 2007 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on May 3 2007
- The UNITED STATES on May 3 2007
- The UNITED KINGDOM on Jun 1 2007
- PAKISTAN on Jul 9 2008
- ISRAEL on Nov 10 2009
- VIET NAM on Nov 21 2009
File Name Aliases
48552331.EXE can also use the following file names:
- DPLWAA~1.EXE
- DPLRQI~1.EXE
- DPLREW~1.EXE
- DPLRNP~1.EXE
- DPLTQW~1.EXE
- DPLTQP~1.EXE
- DPLTWW~1.EXE
- DPLTWI~1.EXE
- RTHDCPL.EXE
- SKYTEL.EXE
- ALCMTR.EXE
- VSNPSTD.EXE
- IKEYMAIN.EXE
- GNOTIFY.EXE
- BILBULON.EXE
- SWEETIM.EXE
- GOOGLETOOLBARNOTIFIER.EXE
- SOCKETÀ¹½ØÆ÷.EXE
- DPLWEA~1.EXE
- CTV924.EXE
- ACROTRAY.EXE
- CTV159.EXE
- NVRTCLK.EXE
- SKYTEL .EXE
- RTHDCPL .EXE
- ACROTRAY .EXE
- _DPTKMMSEST-640.PMS.EXE
- _DPLWNWIBRC-373.PMS.EXE
- B .EXE
- 86073357.SVD
Filesizes
The following file size has been seen:
- 76,284 bytes
- 69,632 bytes
- 159,744 bytes
- 81,920 bytes
- 37,390 bytes
File Type
The filename 48552331.EXE is used by multiple object types including executable programs,objects.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.