Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
TCPTEST.EXE has been seen to perform the following behavior:
- Copies files
- This Process Deletes Other Processes From Disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Registers a Dynamic Link Library File
- Drops known malicious software during execution
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
TCPTEST.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Copied to multiple locations on the system
- Deleted as a process from disk
- Registered as a Dynamic Link Library File
Country Of Origin
The filename TCPTEST.EXE was first seen on Aug 30 2007 in the following geographical regions of the Webroot community:
- on Aug 30 2007
- Europe on Mar 17 2008
- Argentina on Oct 8 2008
- Algeria on Jul 4 2009
- Spain on Jul 4 2009
- Romania on Mar 6 2010
- Thailand on May 19 2012
- Asia/Pacific Region on May 19 2012
File Name Aliases
TCPTEST.EXE can also use the following file names:
- TEMP022.EXE
- ODBCAD32.EXE
- MNMSRVC.EXE
- SNMP.EXE
- ASR_PFU.EXE
- RELOG.EXE
- Æ–°È³‡Æ–™Å¤¾
- 77008456.EXE
Filesizes
The following file size has been seen:
- 102,400 bytes
- 59,115 bytes
- 41,019 bytes
- 45,115 bytes
- 105,226 bytes
- 155,648 bytes
- 28,672 bytes
File Type
The filename TCPTEST.EXE refers to many versions of an executable program.
File Activity
One or more files with the name TCPTEST.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\file0a0.dat
- Deletes c:\program files\installshield installation information\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setup.exe
- Copies filec:\windows\temp022.exe to c:\program files\installshield installation information\{f132af7f-7bca-4ede-8a7c-958108fe7dbc}\setup.exe
- Deletes c:\windows\temp022.ex
- Deletes c:\program files\messenger\msmsgs.exe
- Copies filec:\windows\temp022.exe to c:\program files\messenger\msmsgs.exe
- Deletes c:\program files\mozilla firefox\uninstall\helper.exe
- Copies filec:\windows\temp022.exe to c:\program files\mozilla firefox\uninstall\helper.exe
- Deletes c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
- Copies filec:\windows\temp022.exe to c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
- Deletes c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
- Copies filec:\windows\temp022.exe to c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
- Deletes c:\program files\msn\msncorefiles\install\msnsusii.exe
- Copies filec:\windows\temp022.exe to c:\program files\msn\msncorefiles\install\msnsusii.exe
- Deletes c:\program files\realtek\audio\installshield\Alcmtr.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\Alcmtr.exe
- Deletes c:\program files\realtek\audio\installshield\MicCal.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\MicCal.exe
- Deletes c:\program files\realtek\audio\installshield\RTHDCPL.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\RTHDCPL.exe
- Deletes c:\program files\realtek\audio\installshield\RTLCPL.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\RTLCPL.exe
- Deletes c:\program files\realtek\audio\installshield\RtlUpd.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\RtlUpd.exe
- Deletes c:\program files\realtek\audio\installshield\SoundMan.exe
- Copies filec:\windows\temp022.exe to c:\program files\realtek\audio\installshield\SoundMan.exe
- Deletes c:\program files\windows media player\setup_wm.exe
- Copies filec:\windows\temp022.exe to c:\program files\windows media player\setup_wm.exe
- Deletes c:\program files\winpcap\Uninstall.exe
- Copies filec:\windows\temp022.exe to c:\program files\winpcap\Uninstall.exe
- Deletes c:\windows\$msi31uninstall_kb893803v2$\msiexec.exe
- Copies filec:\windows\temp022.exe to c:\windows\$msi31uninstall_kb893803v2$\msiexec.exe
- Deletes c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb815304$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb815304$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb885222$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb885222$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb886199$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb886199$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb888111wxpsp2$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb888111wxpsp2$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb889673$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb889673$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb895246$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb895246$\spuninst\spuninst.exe
- Deletes c:\windows\$ntuninstallkb896358$\hh.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb896358$\hh.exe
- Deletes c:\windows\$ntuninstallkb896358$\spuninst\spuninst.exe
- Copies filec:\windows\temp022.exe to c:\windows\$ntuninstallkb896358$\spuninst\spuninst.exe
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.