Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Information Stealer
- Fraudulent Security Program
- Malware Downloader
- Malware Dropper
- Worm
File Behavior
F.TMP has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Can communicate with other computer systems using HTTP protocols
- Adds products to the system registry
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Copies files
- This Process is a file infector which modifies program files to include a copy of the infection
- Registers a Dynamic Link Library File
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Opens browser pop ups
- Uses DNS to retrieve the IP address for web sites
- Visits web sites on your PC without you knowing
F.TMP has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Created and Registered as a Browser Helper Object in Internet Explorer
- Has code inserted into its Virtual Memory space by other programs
- Copied to multiple locations on the system
- Added as a Registry auto start to load Program on Boot up
- Added as a Registry Key (RUNONCE) to auto start Programs on system start up
- Created as a new Background Service on the machine
- Loaded and Executed as a System Driver File
- Terminated as a Process
- Registered as a Dynamic Link Library File
Country Of Origin
The filename F.TMP was first seen on May 31 2007 in the following geographical regions of the Webroot community:
- Italy on May 31 2007
- Europe on May 31 2007
- The United States on Sep 9 2007
- Spain on Mar 5 2008
- Canada on Mar 5 2008
- The United Kingdom on Dec 20 2009
- Mexico on Dec 20 2009
- Bosnia and Herzegovina on Jan 20 2010
- Turkey on May 21 2012
Filesizes
The following file size has been seen:
- 54,784 bytes
- 84,127 bytes
- 96,768 bytes
- 36,864 bytes
- 430,080 bytes
- 9,804 bytes
- 25,600 bytes
- 43,713 bytes
File Type
The filename F.TMP is used by multiple object types including executable programs,Dynamic Link LIbraries,objects.
File Activity
One or more files with the name F.TMP creates, deletes, copies or moves the following files and folders:
- Copies filec:\windows\system32\user32.DLL to c:\windows\system32\xxxn
- Creates c:\windows\system32\nvrsol32.dll
- Moves c:\windows\system32\user32.DLL to c:\windows\system32\intkqw
- Copies filec:\windows\system32\xxxn to c:\windows\system32\dllcache\user32.dll
- Copies filec:\windows\system32\xxxn to c:\windows\system32\user32.DLL
- Deletes c:\windows\system32\xxxn
- Creates c:\windows\system32\io.e18
- Creates c:\windows\system32\mnax.hel
- Creates c:\windows\system32\ffcty.sp
- Creates c:\windows\system32\onmac.frv
- Creates c:\windows\system32\can.sdr
- Opens/modifes c:\autoexec.bat
- Copies filec:\windows\system32\paso.el to \\BECKY-890DC1AB\D$\MarioForever.exe
- Copies filec:\windows\system32\paso.el to \\BECKY-890DC1AB\ADMIN$\system32\cls.exe
- Creates c:\docume~1\user\locals~1\temp\tmp13.tmp
- Creates c:\windows\system32\wbem\autorecover\88744D2A29102FC88ECF505DD2E984FC.mof
- Deletes c:\docume~1\user\locals~1\temp\tmp13.tmp
- Creates c:\docume~1\user\locals~1\temp\tmp1B.tmp
- Creates c:\windows\system32\wbem\autorecover\C8463ECBE33BC240263A0B094E46D510.mof
- Deletes c:\docume~1\user\locals~1\temp\tmp1B.tmp
- Creates c:\docume~1\user\locals~1\temp\tmp72.tmp
- Creates c:\windows\system32\wbem\autorecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- Deletes c:\docume~1\user\locals~1\temp\tmp72.tmp
Network Activity
One or more files with the name F.TMP performs the following network events:
- DNS Lookup1.1.18.1 " resulting_addr=
- DNS Lookup1.1.18.1 JENNY-116F1BC6
Website Activity
One or more files with the name F.TMP interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- Remote server connection to 91 .203 .93 .4
- Port 80 IP:91.203.93.41
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.