Associated Malware Groups
The filename is associated with the malware group:
File Behavior
AQOEERW.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Violates Windows/Vista Physical Memory Protection allowing it to look inside the data areas of other programs
- This Process Deletes Other Processes From Disk
- Executes a Process
- Copies files
- Injects code into other processes
- Found on infected systems and resists interrogation by security products
- Registers a Dynamic Link Library File
AQOEERW.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Executed from Temporary Folders
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- This program is often downloaded from the web
- Copied to multiple locations on the system
- Terminated as a Process
- Registered as a Dynamic Link Library File
Country Of Origin
The filename AQOEERW.EXE was first seen on Oct 14 2009 in the following geographical regions of the Prevx community:
- Hong Kong on Oct 14 2009
- Taiwan on Oct 16 2009
- Canada on Nov 25 2009
File Name Aliases
AQOEERW.EXE can also use the following file names:
- DPLYNM~1.EXE
- C__3CE.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__3CE.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__3CE.EXE
- EADF6S.EXE
- SIE2V8.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__SIE2V8.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__WINDOWS_SYSTEM32_AQOEERW.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__SIE2V8.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__WINDOWS_SYSTEM32_AQOEERW.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__SIE2V8.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~0_SUSPECT_SOS_C__WINDOWS_SYSTEM32_AQOEERW.EXE
- C__DOCUME~1_ADMINI~1_LOCALS~1_TEMP_K2E~285719_SUSPECT_SOS_C__SIE2V8.EXE
- C__SIE2V8.EXE
- PYTNMK.EXE
- DPLYAS~1.EXE
- K9CUOS2Q.EXE
- AUTORUN.INF
- N89F1D1W.EXE
- DQI.EXE
- A1.EXE
- 8GIDY.EXE
- 3CE.EXE
Filesizes
The following file size has been seen:
- 100,352 bytes
- 129,070 bytes
- 125,302 bytes
- 126,656 bytes
- 129,209 bytes
- 129,886 bytes
- 114,688 bytes
File Type
The filename AQOEERW.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.