Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Worm
- Malware Downloader
- Malicious Software
File Behavior
333.EXE has been seen to perform the following behavior:
- Found on infected systems and resists interrogation by security products
- Executes a Process
- The Process is packed and/or encrypted using a software packing process
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Reads email address and phone book details
- Drops known malicious software during execution
- Drops or installs rogue security products
- Disables or impairs the normal operation of the Windows Security Center
- Opens browser pop ups
333.EXE has been the subject of the following behavior:
- Created as a new Background Service on the machine
- Executed as a Process
- Created as a process on disk
- Created by processes which appear to be checking for interception by security products
- This program is often downloaded from the web
Country Of Origin
The filename 333.EXE was first seen on Aug 18 2007 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Aug 18 2007
- SPAIN on Nov 2 2007
- FRANCE on Sep 11 2009
- VIET NAM on Nov 20 2009
File Name Aliases
333.EXE can also use the following file names:
- CEUIVQRG.SYS
- 333[n].EXE
- 300.EXE
- 47297447.EXE
Filesizes
The following file size has been seen:
- 27,648 bytes
- 79,872 bytes
- 525,312 bytes
- 61,440 bytes
- 108,393 bytes
- 820 bytes
- 106,499 bytes
- 104,963 bytes
File Type
The filename 333.EXE refers to many versions of an executable program.
File Activity
One or more files with the name 333.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\IEXPLORE.EXE
- Opens/modifes c:\autoexec.bat
- Creates c:\docume~1\user\locals~1\temp\00000e0400000e74.ur
- Deletes c:\docume~1\user\locals~1\temp\00000e0400000e74.ur
- Creates c:\docume~1\user\locals~1\temp\00000e0400000c78.ur
- Deletes c:\docume~1\user\locals~1\temp\00000e0400000c78.ur
- Creates c:\documents and settings\user\desktop\WinPC Defender.LNK
- Creates c:\documents and settings\user\start menu\WinPC Defender.LNK
- Creates c:\documents and settings\user\local settings\application data\GDIPFONTCACHEV1.DAT
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.