Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Internet Chat Cloaked Malware
- Malware Dropper
- Malicious Software
File Behavior
X[1].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Found on infected systems and resists interrogation by security products
- Uses rootkit techniques to conceal its presence, interrogation or removal
- This process creates other processes on disk
- Executes a Process
- Registers a Dynamic Link Library File
- Looks at the contents of the autoexec.bat file
- Visits web sites on your PC without you knowing
- This Process uses Anti Dissasembly Tricks to avoid analysis by security products
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Adds a Registry Key (RUN) to auto start Programs on system start up
X[1].EXE has been the subject of the following behavior:
Country Of Origin
The filename X[1].EXE was first seen on May 20 2007 in the following geographical regions of the Prevx community:
- GERMANY on May 20 2007
- SPAIN on May 20 2007
- The UNITED STATES on Mar 17 2008
- MEXICO on Aug 5 2009
- URUGUAY on Sep 22 2009
- The UNITED KINGDOM on Oct 3 2009
- The EUROPEAN UNION on Nov 6 2009
File Name Aliases
X[1].EXE can also use the following file names:
- DLLRUN32.EXE
- W3KORGOS.VXE
- N1|00UU8ELOQU (nn).EXE
- GLPS.EXE
- FLASH-INSTALLER-WINDOWS.EXE
- FLASH-INSTALLER-WINDOWS[n].EXE
- FLASH-INSTALLER-WINDOWS (n).EXE
- MWAU.EXE
- AUTORUN.EXE
- X[3].EXE
- X[2].EXE
- X.EXE
- 3.TMP
- 72.TMP
- 067.EXE
- 075.EXE
- 328.EXE
- 677.EXE
- 940.EXE
- 454.EXE
- B0MC9QKL.EXE.PART
- L7|X.EXE
- ~TM91.TMP
Filesizes
The following file size has been seen:
- 110,592 bytes
- 116,736 bytes
- 25,600 bytes
- 11,391 bytes
- 124,928 bytes
- 32,256 bytes
- 140,288 bytes
File Type
The filename X[1].EXE refers to many versions of an executable program.
File Activity
One or more files with the name X[1].EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\yjwg9rl.dll
- Creates c:\docume~1\user\locals~1\temp\gz1l7d.exe
- Creates c:\docume~1\user\locals~1\temp\855417142.exe
- Opens/modifes c:\autoexec.bat
- Deletes c:\docume~1\user\locals~1\temp\855417142.exe
- Deletes c:\docume~1\user\locals~1\temp\epz5xm.exe
- Copies filec:\docume~1\user\locals~1\temp\gz1l7d.exe to c:\docume~1\user\locals~1\temp\epz5xm.exe
- Creates c:\docume~1\user\locals~1\temp\habnf88jkefh87ifiks.tmp
- Creates c:\docume~1\user\locals~1\temp\952448392.exe
- Deletes c:\docume~1\user\locals~1\temp\952448392.exe
- Deletes c:\docume~1\user\locals~1\temp\winlogon.exe
- Copies filec:\docume~1\user\locals~1\temp\855417142.exe to c:\docume~1\user\locals~1\temp\winlogon.exe
- Deletes c:\docume~1\user\locals~1\temp\login.exe
- Copies filec:\docume~1\user\locals~1\temp\855417142.exe to c:\docume~1\user\locals~1\temp\login.exe
- Deletes c:\docume~1\user\locals~1\temp\mdm.exe
- Copies filec:\docume~1\user\locals~1\temp\855417142.exe to c:\docume~1\user\locals~1\temp\mdm.exe
- Creates c:\docume~1\user\locals~1\temp\jisfije9fjoiee.tmp
Website Activity
One or more files with the name X[1].EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- virtualmits .com / ndw / vp1 .php?id=1CA489931759F8E&ver=v10&er=S_wd_rd_we_re_
- Port 80 IP:94.75.207.170
- wscntgy .com / fn / gz .php?ver=H4
- Remote server connection to wscntgy .co
- Port 80 IP:95.211.1.38
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.