Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malware Downloader
File Behavior
IC.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- Reads email address and phone book details
- Includes file creation code which could be used to test for interception by security products
- Visits web sites on your PC without you knowing
IC.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Created by processes which appear to be checking for interception by security products
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Executed from Temporary Folders
Country Of Origin
The filename IC.EXE was first seen on May 26 2007 in the following geographical regions of the Webroot community:
- Turkey on May 26 2007
- on Oct 17 2007
- Spain on Mar 20 2009
- The United States on Mar 20 2009
- Uruguay on May 29 2009
- Netherlands on Dec 11 2009
- Thailand on May 10 2013
File Name Aliases
IC.EXE can also use the following file names:
- HAHA.EXE
- HA HA !.EXE
- NASCONDE TUTTE LE ICONE DEL DESKTOP.EXE
- DESKTOP.EXE
- S_HAHA.EXE
- HEMEN MASAUSTU HAHA.EXE
- GÖRÜNMEZLIK.EXE
- ICOMPOSITE.EXE
- NASCONDI_DESKTOP.EXE
- TASKMGR.EXE
- EXREV.EXE
- CONVERTER7.EXE
- CTFMON.EXE
- SVCHOST.EXE
- BODVDDL.EXE
- BOAPPSDL.EXE
- BPFULL.EXE
- IC[n].EXE
- CB.EXE
- EP.EXE
- IC2.EXE
- 04D2YFLR.EXE
- E4U.EXE
- 00382834.DAT
- 90257941.EXE
- 71940528.EXE
Filesizes
The following file size has been seen:
- 110,592 bytes
- 1,890,304 bytes
- 146,536 bytes
- 9,248 bytes
- 48,640 bytes
- 10,240 bytes
File Type
The filename IC.EXE is used by multiple object types including objects,executable programs,objects.
File Activity
One or more files with the name IC.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\cscript.exe
- Creates c:\windows\system32\yhafd78auhd.dll
- Creates c:\docume~1\user\locals~1\temp\zjhufhdfe.exe
- Deletes c:\docume~1\user\locals~1\temp\2807809080.exe
- Creates c:\p2hhr.bat
- Deletes c:\docume~1\user\locals~1\temp\fj38bc4iwo.exe
- Copies filec:\docume~1\user\locals~1\temp\zjhufhdfe.exe to c:\docume~1\user\locals~1\temp\fj38bc4iwo.exe
- Copies filec:\windows\system32\drivers\beep.sys to c:\docume~1\user\locals~1\temp\46.tmp
- Creates c:\windows\system32\drivers\beep.sys
- Copies filec:\docume~1\user\locals~1\temp\46.tmp to c:\windows\system32\drivers\beep.sys
- Deletes c:\docume~1\user\locals~1\temp\46.tmp
- Copies filec:\windows\system32\drivers\null.sys to c:\docume~1\user\locals~1\temp\4B.tmp
- Creates c:\windows\system32\drivers\null.sys
- Copies filec:\docume~1\user\locals~1\temp\4B.tmp to c:\windows\system32\drivers\null.sys
- Deletes c:\docume~1\user\locals~1\temp\4B.tmp
- Creates c:\windows\system32\drivers\glaide32.sys
- Deletes c:\kkbgiekw.exe
- Moves c:\kkbgiekw.exe to c:\docume~1\user\locals~1\temp\55.tmp
- Creates c:\docume~1\user\locals~1\temp\asfdvcxzedbfkjd.tmp
- Deletes c:\docume~1\user\locals~1\temp\2821559080.exe
- Creates c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf42.tmp
- Creates c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf35.log
- Moves c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf35.log to c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf43.exe
- Creates c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf36.log
- Moves c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf36.log to c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf44.exe
- Deletes c:\docume~1\user\locals~1\temp\2857496580.exe
- Creates c:\windows\system32\reader_s.exe
- Creates c:\documents and settings\user\reader_s.exe
- Creates c:\windows\ld08.exe
- Creates c:\487656.bat
- Deletes c:\qjysgnhd.exe
- Deletes c:\p2hhr.bat
- Deletes c:\windows\ld49f4d98.da
- Deletes c:\windows\st_1243674123.exe
- Deletes c:\dfhd.exe
- Deletes c:\487656.bat
- create folder c:\program Files\
- create folder c:\program Files\ThunMail
- Creates c:\program files\thunmail\testabd.dll
- Copies filec:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf43.exe to c:\program files\thunmail\testabd.exe
- Creates c:\docume~1\user\locals~1\temp\xswedfvbnjhrfliuyf43.exe
- Deletes c:\docume~1\user\locals~1\temp\XSWEDF~1.EXE
- Deletes c:\docume~1\user\locals~1\temp\XSWEDF~1.BA
Network Activity
One or more files with the name IC.EXE performs the following network events:
- DNS Lookup209.85.227.147 www.google.com
- DNS Lookup119.110.107.137 main15052009.com
Website Activity
One or more files with the name IC.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- agixtudkco .com / progs / spyzma / eolcpqqu .php?adv=adv721
- agixtudkco .com / progs / spyzma / udeee .php
- agixtudkco .com / progs / spyzma / syvvw .php
- agixtudkco .com / progs / spyzma / jyiifgkxhy .php
- agixtudkco .com / progs / spyzma / jtcqqe .php
- agixtudkco .com / progs / spyzma / voclzzjkg .php
- agixtudkco .com / progs / spyzma / iobpgg .php
- agixtudkco .com / progs / spyzma / nkklpcghhv
- agixtudkco .com / progs / spyzma / tmzaa .php?adv=adv721&code1=JQR0&code2=9403&id=483654851&p=0
- Port 80 IP:195.2.253.236
- TCP:127.0.0.1:1355 Port:16
- TCP:210.51.51.150:88 Port:17
- Port 80 IP:210.51.51.150
- Port 80 IP:74.52.164.210
- Port 80 IP:209.85.227.147
- Port 80 IP:119.110.107.137
- Port 80 IP:221.12.89.137
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.