File Behavior
RR.EXE has been seen to perform the following behavior:
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- Registers a Dynamic Link Library File
- Creates new folders in the file system
- Creates a new Background Service on the machine
- Looks at the contents of the autoexec.bat file
- Drops known malicious software during execution
- Reads email address and phone book details
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- The Process is packed and/or encrypted using a software packing process
- Downloads program file(s) and other content from the web
- Uses DNS to retrieve the IP address for web sites
- Includes file creation code which could be used to test for interception by security products
- The Process is polymorphic and can change its structure
RR.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Created as a new Background Service on the machine
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename RR.EXE was first seen on Jul 7 2007 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Jul 7 2007
- SPAIN on Apr 4 2009
- The UNITED KINGDOM on Apr 7 2009
Filesizes
The following file size has been seen:
- 2,478,080 bytes
- 21,704 bytes
- 188,416 bytes
- 3,494,456 bytes
File Type
The filename RR.EXE refers to many versions of an executable program.
File Activity
One or more files with the name RR.EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
- create folder c:\program Files\
- create folder c:\program Files\ThunMail
- Creates c:\program files\thunmail\testabd.dll
- Copies filec:\docume~1\user\locals~1\temp\w1w1.exe to c:\program files\thunmail\testabd.exe
- Creates c:\docume~1\user\locals~1\temp\w1w1.exe
- Deletes c:\docume~1\user\locals~1\temp\w1w1.exe
- Deletes c:\docume~1\user\locals~1\temp\W1W1EX~1.BAT
- Creates c:\docume~1\user\locals~1\temp\w1w1.exe.bat
- Deletes c:\windows\system32\usbcom.sys
- Deletes c:\windows\system32\usbdisk.sys
- Deletes c:\windows\system32\autocad.sys
- Deletes c:\windows\system32\apcisvr.sys
- Deletes c:\windows\system32\nidsdrv.sys
- Deletes c:\windows\system32\pcistub.sys
- Creates c:\windows\temp\clk604.nls
- Moves c:\windows\temp\clk604.nls to c:\windows\system32\at1394.sys
- Deletes c:\windows\system32\6to4v32.dll
- Creates c:\windows\temp\clk527.nls
- Moves c:\windows\temp\clk527.nls to c:\windows\system32\6to4v32.dll
- Deletes c:\docume~1\user\locals~1\temp\zha.exe
- Creates c:\docume~1\user\locals~1\temp\ipk.bat
- Deletes c:\docume~1\user\locals~1\temp\ipk.exe
- Deletes c:\docume~1\user\locals~1\temp\ipk.bat
Website Activity
One or more files with the name RR.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1065 Port:17
- Port 80 IP:67.228.214.67
- Port 80 IP:218.6.9.120
- Port 80 IP:72.167.145.240
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.