Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
- Virus
- Malware Downloader
File Behavior
TESTE1_P.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- Executes a Process
- Registers a Dynamic Link Library File
- Copies files
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- Executes Processes stored in Temporary Folders
- Can communicate with other computer systems using HTTP protocols
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
TESTE1_P.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Copied to multiple locations on the system
- Executed from Temporary Folders
- Victim of a Heap Based Buffer Overflow Exploit
Country Of Origin
The filename TESTE1_P.EXE was first seen on Oct 14 2007 in the following geographical regions of the Webroot community:
- Europe on Oct 14 2007
- Belgium on Nov 22 2007
- Canada on Nov 22 2007
- Israel on May 25 2009
- Hungary on May 25 2009
- Italy on Feb 26 2010
- The United States on Feb 26 2010
- The United Kingdom on Apr 1 2010
- Brazil on Apr 1 2010
- Germany on Apr 8 2010
File Name Aliases
TESTE1_P.EXE can also use the following file names:
- LSASS.EXE
- TMP5240169.LOG
- TMP7123972.LOG
- TMP7740406.LOG
- SVHOSTER.EXE
- TMP3152934.LOG
- CSI14.TMP
- CSI21.TMP
- TMP5470214.LOG
- TMP2709597.LOG
- LSASS .EXE
- 01CAD358263073E4_TESTE1_P_EXE.PE
Filesizes
The following file size has been seen:
- 280,576 bytes
- 253,952 bytes
- 200,704 bytes
- 374,272 bytes
- 353,792 bytes
- 225,280 bytes
- 330,240 bytes
- 201,728 bytes
File Type
The filename TESTE1_P.EXE refers to many versions of an executable program.
File Activity
One or more files with the name TESTE1_P.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\82e7_appcompat.txt
- Creates c:\docume~1\user\locals~1\temp\18FB8.dmp
- Opens/modifes c:\autoexec.bat
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.