Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
WINSSLED.EXE has been seen to perform the following behavior:
- Disables the built in Windows File Protection System
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Injects code into other processes
- Copies files
- Sets processes to start during user logon
- Disables the Notification Balloon for the Windows Security Center
- Disables Access to the Task Manager built into Windows
- Disables Access to the Windows Registry Editior
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Adds products to the system registry
- Executes Processes stored in Temporary Folders
- Found on infected systems and resists interrogation by security products
WINSSLED.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Copied to multiple locations on the system
- Executed from Temporary Folders
Country Of Origin
The filename WINSSLED.EXE was first seen on Nov 19 2009 in the following geographical regions of the Prevx community:
- Brazil on Nov 19 2009
- Chile on Nov 19 2009
- Vietnam on Nov 20 2009
- The United Kingdom on Nov 20 2009
- Egypt on Nov 24 2009
- Mexico on Nov 26 2009
- Georgia on Nov 27 2009
- Australia on Feb 10 2010
File Name Aliases
WINSSLED.EXE can also use the following file names:
- TYHSSWC[1].EXE
- HSYSJSWOPC[1].EXE
- WINSSLED .EXE
- HSYSJSWOPC.EXE
- IEYEWWMC.EXE
- IEYEWWMC_001.EXE
- KSOSLPC[1].EXE
- IEYEWWMC[1].EXE
- 448.EXE
- 657.EXE
- 922.EXE
- 708.EXE
- 362.EXE
- 220.EXE
- 206.EXE
- 08138291.EXE
Filesizes
The following file size has been seen:
- 65,024 bytes
- 79,872 bytes
- 79,360 bytes
- 141,824 bytes
- 62,464 bytes
- 41,472 bytes
- 44,544 bytes
- 38,356 bytes
File Type
The filename WINSSLED.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.