Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malware Downloader
- Malicious Software
File Behavior
B4.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Uses hidden browser windows to connect to web sites without telling you
- Opens browser pop ups
- Runs Javascript code
- Visits web sites on your PC without you knowing
- Executes a Process
B4.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Registered as a Dynamic Link Library File
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename B4.EXE was first seen on Jan 4 2008 in the following geographical regions of the Webroot community:
- Brazil on Jan 4 2008
- China on Jan 12 2008
- Italy on Dec 20 2008
- on Aug 25 2009
- South Africa on Oct 29 2011
- The United States on Oct 29 2011
- Turkey on May 21 2012
File Name Aliases
B4.EXE can also use the following file names:
- SVCHOST.EXE
- FIREFOX.EXE
- B3.EXE
- B5.EXE
- B78A.EXE
- CB88.EXE
- E870.EXE
- A5E4.EXE
- B96.EXE
- B97.EXE
- B9A.EXE
- B9B.EXE
- B9C.EXE
- B9D.EXE
- B9E.EXE
- F017.EXE
- ~TMPB.EXE
- 52D3.EXE
- EE87.EXE
- B362.EXE
- DF9141.EXE
- DF9142.EXE
- DF9143.EXE
- 88681588.EXE
- 14339508.EXE
- 02376607.DAT
Filesizes
The following file size has been seen:
- 106,496 bytes
- 90,116 bytes
- 527,273 bytes
- 327,680 bytes
- 26,112 bytes
- 32,614 bytes
- 100,356 bytes
- 38,400 bytes
- 30,720 bytes
File Type
The filename B4.EXE is used by multiple object types including executable programs,objects,objects.
File Activity
One or more files with the name B4.EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
Website Activity
One or more files with the name B4.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- Remote server connection to imagesrepository .co
- Remote server connection to stockshopimages .co
- Remote server connection to delphiner .co
- Remote server connection to images-base .co
- Remote server connection to 68 .169 .70 .13
- Remote server connection to www .asklots .co
- TCP:127.0.0.1:1115 Port:23
- Port 80 IP:216.240.157.91
- Port 80 IP:216.240.143.20
- Port 80 IP:68.169.70.134
- Port 80 IP:67.29.139.153
- Remote server connection to massembler .co
- Remote server connection to www .myshovel .co
- Remote server connection to 206 .161 .121 .11
- Remote server connection to www .abcsearch .co
- Remote server connection to www .blinkx .co
- Remote server connection to bighomesearch .co
- Remote server connection to 66 .230 .188 .6
- Remote server connection to 66 .230 .188 .12
- Remote server connection to 68 .169 .70 .24
- Remote server connection to www .locatewebsearch .ne
- TCP:127.0.0.1:1181 Port:22
- Port 80 IP:66.96.216.54
- Port 80 IP:213.174.149.120
- Port 80 IP:66.150.51.167
- Port 80 IP:64.150.189.162
- Port 80 IP:66.230.188.67
- Port 80 IP:66.230.188.123
- Port 80 IP:68.169.70.241
- Port 80 IP:213.174.149.70
- Remote server connection to www .searchswitch .co
- Remote server connection to atl .mv .bidsystem .co
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.