Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
DC30.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This process creates other processes on disk
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Writes to another Process's Virtual Memory (Process Hijacking)
- Loads and Executes a System Driver File
- This Process Deletes Other Processes From Disk
- Creates a new Background Service on the machine
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Registers a Windows APPINIT DLL To be loaded in all processes
- Adds a Registry Key (RUNONCE) to auto start Programs on system start up
- Modifies System Runtime Policies to limit system usability
- Registers a Dynamic Link Library File
- Executes a Process
- Injects code into other processes
- Reads your outlook address book
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Creates system tray popups, messages, errors and security warnings
DC30.EXE has been the subject of the following behavior:
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Created as a process on disk
- Deleted as a process from disk
- Executed from Temporary Folders
- Added as a Service in the System Registry Current Control Set
- Created as a new Background Service on the machine
- Copied to multiple locations on the system
Country Of Origin
The filename DC30.EXE was first seen on Jul 3 2007 in the following geographical regions of the Webroot community:
- South Africa on Jul 3 2007
- Europe on Jul 19 2007
- Poland on Jul 19 2007
- Hungary on Oct 31 2007
- Austria on Oct 31 2007
- The United States on Nov 29 2007
- Egypt on May 3 2012
File Name Aliases
DC30.EXE can also use the following file names:
- CATCHME.EXE
- CATCHME.CFEXE
- 22458204.EXE
- 68295984.EXE
Filesizes
The following file size has been seen:
- 140,288 bytes
- 185,344 bytes
- 109,056 bytes
- 104,960 bytes
- 32,768 bytes
- 136,192 bytes
File Type
The filename DC30.EXE is used by multiple object types including objects,executable programs.
File Activity
One or more files with the name DC30.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\rgbkllrnE6DE859.dll
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.