Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- System Back Door
- Cloaked Malware
- Malicious Software
File Behavior
S3.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- The Process is polymorphic and can change its structure
- Executes a Process
- Communicates with other computers using FTP connections
- Creates a TCP port which listens and is available for communication initiated by other computers
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Includes file creation code which could be used to test for interception by security products
- Reads email address and phone book details
S3.EXE has been the subject of the following behavior:
- Deleted as a process from disk
- Executed as a Process
- Created as a process on disk
- Added as a Registry auto start to load Program on Boot up
- Created by processes which appear to be checking for interception by security products
- Copied to multiple locations on the system
Country Of Origin
The filename S3.EXE was first seen on Jun 5 2007 in the following geographical regions of the Webroot community:
- Netherlands on Jun 5 2007
- The United Kingdom on Jun 5 2007
- Australia on Oct 15 2007
- Spain on Oct 17 2008
- The United States on Nov 1 2009
- Philippines on Feb 2 2010
- Puerto Rico on Apr 22 2012
Filesizes
The following file size has been seen:
- 1,093,632 bytes
- 1,186,304 bytes
- 866,034 bytes
- 709,688 bytes
- 389,628 bytes
- 14,343 bytes
- 38,912 bytes
File Type
The filename S3.EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name S3.EXE creates, deletes, copies or moves the following files and folders:
- Moves c:\windows\system32\lssas.exe to \system32\lssas.exe
- Moves c:\windows\system32\wbem\fonts.exe to c:\windows\system32\fonts.exe
- Copies filec:\windows\system32\fonts.exe to c:\windows\system32\wbem\fonts.exe
- Copies filec:\windows\system32\fonts.exe to c:\windows\cursors\beifen.exe
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.