Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
DDEXPSHARE.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Changes the Windows Security Center settings to ensure that Antivirus status alerts are activated
- Injects code into other processes
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes Processes stored in Temporary Folders
- Can communicate with other computer systems using HTTP protocols
DDEXPSHARE.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Registered as a Dynamic Link Library File
- Created as a process on disk
- Executed from Temporary Folders
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename DDEXPSHARE.EXE was first seen on Feb 6 2010 in the following geographical region of the Prevx community:
- The United States on Feb 6 2010
File Name Aliases
DDEXPSHARE.EXE can also use the following file names:
- BDFC.EXE
- BDFB.EXE
- EEEF.EXE
- DDEXPSHARE .EXE
- A3C7.EXE
- D164.EXE
- E7E1.EXE
- 9DE1.EXE
- DHDHTRDHDRTR5Y
- 83571418.EXE
Filesizes
The following file size has been seen:
- 786,432 bytes
- 790,528 bytes
File Type
The filename DDEXPSHARE.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.