Associated Malware Groups
The filename is associated with the malware groups:
File Behavior
13D.TMP has been seen to perform the following behavior:
- Uses hidden browser windows to connect to web sites without telling you
- Creates system tray popups, messages, errors and security warnings
- Opens browser pop ups
- Runs Javascript code
- Visits web sites on your PC without you knowing
- The Process is packed and/or encrypted using a software packing process
13D.TMP has been the subject of the following behavior:
- Executed as a Process
- Copied to multiple locations on the system
- Added as a Registry auto start to load Program on Boot up
Country Of Origin
The filename 13D.TMP was first seen on Dec 2 2008 in the following geographical regions of the Webroot community:
- Argentina on Dec 2 2008
- Uruguay on Mar 5 2009
- Belgium on Jun 5 2009
- Spain on Jun 5 2009
- India on May 21 2012
File Name Aliases
13D.TMP can also use the following file names:
- B.EXE
- 19.TMP
- 88.TMP
- 13.TMP.EXE
- DC84.TMP
- 85E.TMP
- 74750938.TMP
Filesizes
The following file size has been seen:
- 126,468 bytes
- 104,960 bytes
- 5,525 bytes
- 24,974 bytes
- 24,261 bytes
File Type
The filename 13D.TMP refers to many versions of an executable program.
File Activity
One or more files with the name 13D.TMP creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
- Opens/modifes c:\autoexec.bat
Website Activity
One or more files with the name 13D.TMP interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- / iframe3?AAAAACNACACNtSQAQCoJAAIAAAAAAP8AAAAGEQIAAgOhKQwAE-QFABIkDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAh-r3zxoLU .CH6vfPGgtT9cPpKSHgbCP1w-kpIeBsI .-SzPg7uzyj .5LM-Du7PKPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAzHmuRkwicgbVqi00iJT4dDmqcHLTQwcxf-7 .ygAAAAA=,,75
- / iframe3?AAAAACNACACHtSQAQCoJAAIAAAAAAP8AAAAGEQIACgOhKQwAE-QFABIkDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAh-r3zxoLU .CH6vfPGgtT9cPpKSHgbCP1w-kpIeBsI .-SzPg7uzyj .5LM-Du7PKPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC-p1fEwicgZ3t6VPBopb-47nGGtS945Ws8dwIQAAAAA=,,75
- / iframe3?AAAAACNACACStSQAQCoJAAIAAAAAAP8AAAAGEQIABgOhKQwAE-QFABIkDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAh-r3zxoLU .CH6vfPGgtT9cPpKSHgbCP1w-kpIeBsI .-SzPg7uzyj .5LM-Du7PKPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAZZbjn0wicgaECvRXSPcnlkhMsKlhNnk7YsJdWQAAAAA=,,75
- / iframe3?RwQAAI9zBwAl2yAAU9wKAAIAAAAAAP8AAAAGEQIABgJUYgsAXn4PAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANA .AAAAAAAA0D-kcD0K16PQP6RwPQrXo9A .AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAZjzD1lEicgY0fiZZCSfE8A2shd5OD .0qTc8CjgAAAAA=,,ad
- / iframe3?RwQAAI9zBwCDCCQAItoKAAIAAAAAAP8AAAAGEQIAAgNUYgsAoKAAAK97DwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANA .AAAAAAAA0D8AAAAAAAAAAOtRKD0iItI .AAAAAAAAAAAyM0O74zjePwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXPMSBk8icgaRd .VUPckV6TbuuQFRUQYKimYnzgAAAAA=,,ad
- / iframe3?AAAAACNACACHtSQAQCoJAAIACAAAAP8AAAAGEQIACgOhKQwAE-QFABIkDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAh-r3zxoLU .CH6vfPGgtT9cPpKSHgbCP1w-kpIeBsI .-SzPg7uzyj .5LM-Du7PKPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHlw2IlIicgb5Ap8Uh2LVaRDTvE2dV7Uz .jneBgAAAAA=,,75
- / iframe3?RwQAAI9zBwCQ2CQA4vYKAAIABAAAAP8AAAAGEQIACgNUYgsA73EAAPyiDwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANA .AAAAAAAA0D-4HoXrUbjOP7gehetRuM4 .mpmZmZmZ2T-amZmZmZnZPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAndb7XlQicgY3w8 .JzLd83IwsRSPkPWwlxl3bQQAAAAA=,,ad
- / sc46 / frame2 .swf?tf_flash=smileyadv .net / sc46 / sc01_468x60_1007 .swf&tf_button=smileyadv .net / sc46 / button2 .swf
- / imp / 10271;6348;201;js;YukayMedia;160x600RON / ?click=ad .reduxmedia .com / click,RwQAAI9zBwCQ2CQA4vYKAAIABAAAAP8AAAAGEQIACgNUYgsA73EAAPyiDwAAAAAAAAAAAAAAAAAAAAAAAAAAANQ9KUoAAAAA,,http%3A%2F%2Fad .yieldmanager .com%2Fiframe3%3Faaaaacnacachtsqaqcojaaiacaaaap
- Remote server connection to imagesrepository .co
- Remote server connection to zone-searching .co
- Remote server connection to www .abcjmp .co
- Remote server connection to www .abcsearch .co
- Remote server connection to www .chinaontv .co
- Remote server connection to 75 .102 .43 .
- Remote server connection to ads .clicksor .co
- Remote server connection to ad .yieldmanager .co
- Remote server connection to pub .clicksor .ne
- Remote server connection to admedia .xmlsearch .findwhat .co
- Remote server connection to serw .clicksor .co
- Remote server connection to partner .googleadservices .co
- Remote server connection to 66 .230 .188 .6
- Remote server connection to pubads .g .doubleclick .ne
- Remote server connection to ad .reduxmedia .co
- Remote server connection to creative .clicksor .co
- Remote server connection to impfr .tradedoubler .co
- Remote server connection to www .blinkx .co
- Remote server connection to hstgb .tradedoubler .co
- Remote server connection to cdn .blinkx .co
- Remote server connection to ad .doubleclick .ne
- Remote server connection to m1 .2mdn .ne
- Remote server connection to content .yieldmanager .edgesuite .ne
- Remote server connection to edge .quantserve .co
- Remote server connection to get .adobe .co
- Remote server connection to pixel .quantserve .co
- Remote server connection to www .adobe .co
- Remote server connection to smileyadv .ne
- Remote server connection to cnt .mtwns .ne
- Remote server connection to servedby .flashtalking .co
- Remote server connection to video .flashtalking .co
- Remote server connection to
- Remote server connection to wwwimages .adobe .co
- Remote server connection to activex .microsoft .co
- Remote server connection to stats .adobe .co
- Remote server connection to abyssmilf .co
- TCP:127.0.0.1:1097 Port:24
- Port 80 IP:216.240.157.91
- Port 80 IP:88.214.205.8
- Port 80 IP:67.29.139.153
- Port 80 IP:216.246.74.250
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.