Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
UNREGAAW.EXE has been seen to perform the following behavior:
- Executes a Process
- This Process Deletes Other Processes From Disk
- Drops known malicious software during execution
- Includes file creation code which could be used to test for interception by security products
- This Process is a file infector which modifies program files to include a copy of the infection
- Uses backdoor interfaces to certain security applications
- Uses functions commonly exploited by Worms
- Uses DNS to retrieve the IP address for web sites
UNREGAAW.EXE has been the subject of the following behavior:
- Deleted as a process from disk
- Created as a process on disk
- Executed as a Process
Country Of Origin
The filename UNREGAAW.EXE was first seen on Mar 17 2008 in the following geographical regions of the Webroot community:
- Europe on Mar 17 2008
- Mexico on Aug 31 2008
- Spain on Apr 6 2009
- Turkey on Apr 22 2013
Filesizes
The following file size has been seen:
- 236,544 bytes
- 162,821 bytes
- 191,897 bytes
- 201,216 bytes
- 168,444 bytes
File Type
The filename UNREGAAW.EXE refers to many versions of an executable program.
File Activity
One or more files with the name UNREGAAW.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\rundl132.exe
- Creates c:\windows\Logo1_.exe
- Deletes c:\docume~1\user\locals~1\temp\$$a9.bat
- Creates c:\docume~1\user\locals~1\temp\$$a9.bat
- Creates c:\windows\vDll.dll
- Creates d:\_desktop.ini
- Creates c:\_desktop.ini
- Creates c:\config.msi\_desktop.ini
- Creates c:\malwarefiles\_desktop.ini
- Creates c:\mbr\_desktop.ini
- Creates c:\program files\_desktop.ini
- Creates c:\program files\adobe\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\reader\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\reader\plug_ins3d\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\reader\plug_ins3d\prc\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\resource\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\resource\cmap\_desktop.ini
- Creates c:\program files\adobe\reader 8.0\resource\font\_desktop.ini
- Creates c:\program files\ati technologies\_desktop.ini
- Creates c:\program files\ati technologies\uninstallall\_desktop.ini
- Creates c:\program files\intel\_desktop.ini
- Creates c:\program files\intel\ans\_desktop.ini
- Creates c:\program files\intel\dmix\_desktop.ini
- Creates c:\program files\intel\dmix\hlp\_desktop.ini
- Creates c:\program files\intel\dmix\resource\_desktop.ini
- Creates c:\program files\intel\dmix\uninst\_desktop.ini
- Creates c:\program files\intel\ncs2\_desktop.ini
- Creates c:\program files\intel\ncs2\agent\_desktop.ini
- Creates c:\program files\intel\ncs2\wmiprov\_desktop.ini
- Creates c:\program files\intel\ncs2\wmiprov\mof\_desktop.ini
- Creates c:\program files\microsoft bootvis\_desktop.ini
- Creates c:\program files\online services\_desktop.ini
- Creates c:\program files\prevx\_desktop.ini
- Creates c:\program files\prevx2\_desktop.ini
- Creates c:\program files\prevx2\dctlibs\_desktop.ini
- Creates c:\program files\prevx2\gfx\_desktop.ini
- Creates c:\program files\prevx2\help\_desktop.ini
- Creates c:\program files\prevx2\html\_desktop.ini
- Creates c:\program files\prevx2\log\_desktop.ini
- Creates c:\program files\prevx2\maitemp\_desktop.ini
- Creates c:\program files\prevx2\modules\_desktop.ini
- Creates c:\program files\prevx2\support\_desktop.ini
- Creates c:\program files\prevx2\support\drivers\_desktop.ini
- Creates c:\program files\prevx2\support\drivers\2k\_desktop.ini
- Creates c:\program files\prevx2\support\drivers\2k3\_desktop.ini
- Creates c:\program files\prevx2\support\drivers\xp\_desktop.ini
- Creates c:\program files\prevx2\translations\_desktop.ini
- Creates c:\program files\prevx2\translations\dutch\_desktop.ini
- Creates c:\program files\prevx2\translations\dutch\gfx\_desktop.ini
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.