Associated Malware Groups
The filename is associated with the malware groups:
File Behavior
X[2].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Creates system tray popups, messages, errors and security warnings
- Uses DNS to retrieve the IP address for web sites
- Visits web sites on your PC without you knowing
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Executes a Process
X[2].EXE has been the subject of the following behavior:
- Executed as a Process
- Copied to multiple locations on the system
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
Country Of Origin
The filename X[2].EXE was first seen on Dec 12 2007 in the following geographical regions of the Prevx community:
- SPAIN on Dec 12 2007
- TURKEY on Sep 24 2009
- BOLIVIA on Nov 19 2009
File Name Aliases
X[2].EXE can also use the following file names:
- GUUPMOX.EXE
- WINUPDATES.EXE
- X[1].EXE
- 17.SCR
- 60301.EXE
- 40202.EXE
- X000.EXE
- 0SVBH.EXE
- 58659883.DAT
- 48537666.DAT
- 47851071.200
- 47175867.200
Filesizes
The following file size has been seen:
- 16,384 bytes
- 24,064 bytes
- 92,638 bytes
- 20,480 bytes
- 167,936 bytes
- 134,242 bytes
File Type
The filename X[2].EXE refers to many versions of an executable program.
File Activity
One or more files with the name X[2].EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
Network Activity
One or more files with the name X[2].EXE performs the following network events:
- DNS Lookup1.1.13.1 SARAH-5B8C77BC
Website Activity
One or more files with the name X[2].EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- citi-bank .ru / index .php?id=zdfogxdqswmewmfe&scn=0&inf=0&ver=19&cnt=USA
- Port 80 IP:89.208.35.28
- TCP:1.1.13.0:445 Port:30
- TCP:1.1.22.213:445 Port:31
- TCP:1.1.36.98:445 Port:31
- TCP:1.1.136.35:445 Port:31
- TCP:1.1.161.186:445 Port:31
- TCP:84.253.138.175:445 Port:33
- TCP:1.1.202.201:445 Port:33
- TCP:1.1.7.100:445 Port:34
- TCP:1.1.13.5:445 Port:34
- TCP:1.1.59.245:445 Port:36
- TCP:1.1.119.19:445 Port:37
- TCP:1.1.13.2:445 Port:37
- TCP:223.245.108.112:445 Port:37
- TCP:186.125.167.223:445 Port:37
- TCP:164.112.125.4:445 Port:33
- TCP:1.1.132.143:445 Port:32
- TCP:192.201.224.118:445 Port:32
- TCP:0.130.93.60:445 Port:32
- TCP:1.1.52.107:445 Port:38
- TCP:1.1.49.121:445 Port:39
- TCP:192.230.82.184:445 Port:39
- TCP:1.1.112.155:445 Port:41
- TCP:1.1.149.210:445 Port:41
- TCP:1.1.13.3:445 Port:39
- TCP:128.155.205.12:445 Port:43
- TCP:1.1.82.86:445 Port:41
- TCP:1.1.177.218:445 Port:41
- TCP:247.204.210.23:445 Port:35
- TCP:219.15.18.2:445 Port:35
- TCP:115.185.51.214:445 Port:43
- TCP:1.1.251.118:445 Port:40
- TCP:79.190.9.205:445 Port:37
- TCP:1.1.13.4:445 Port:41
- TCP:184.4.118.218:445 Port:41
- TCP:1.1.31.199:445 Port:45
- TCP:1.1.251.5:445 Port:36
- TCP:96.196.230.125:445 Port:36
- TCP:212.204.101.155:445 Port:36
- TCP:1.1.61.23:445 Port:41
- TCP:233.120.255.235:445 Port:41
- TCP:96.95.14.98:445 Port:41
- TCP:45.225.35.106:445 Port:42
- TCP:200.46.97.117:445 Port:42
- TCP:28.101.207.50:445 Port:39
- TCP:88.131.52.164:445 Port:39
- TCP:61.196.182.218:445 Port:45
- TCP:192.32.131.43:445 Port:45
- TCP:231.174.213.233:445 Port:45
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.