Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
SESK.EXE has been seen to perform the following behavior:
- Executes a Process
- This Process Deletes Other Processes From Disk
- Copies files
- Injects code into other processes
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Installs a browser helper object (BHO)
- Creates new folders on the system
- Writes to another Process's Virtual Memory (Process Hijacking)
SESK.EXE has been the subject of the following behavior:
- Executed as a Process
- Copied to multiple locations on the system
- Created as a process on disk
- Deleted as a process from disk
- Created as a new Background Service on the machine
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename SESK.EXE was first seen on Nov 2 2009 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Nov 2 2009
- URUGUAY on Nov 3 2009
- The UNITED STATES on Nov 5 2009
- VIET NAM on Nov 7 2009
- MEXICO on Nov 7 2009
- AUSTRIA on Nov 20 2009
- GREAT BRITAIN on Nov 20 2009
File Name Aliases
SESK.EXE can also use the following file name:
- FPOFMUM.EXE
- ANSIL.EXE
- EEAKCOW.EXE
- AAAAMONR.EXE
- ACCTRESG.EXE
- ACLEDITK.EXE
- GQQRV[1].HTM
- AC3ACMP.EXE
- AMCOMPATV.EXE
- ACTIVEDSC.EXE
- ADOBEPDFK.EXE
- VBUNNX[1].HTM
- ULXF.EXE
- ALRSVCX.EXE
- RCDHAR.EXE
- WNZIP32.EXE
- SPEOONTY.EXE
- JYFOL[1].HTM
- CMXMWFG.EXE
- AUTORUN.EXE
- LQEKSNHP.EXE
- UHTSP.EXE
- TCYC.EXE
- BVOKDG.EXE
- UBFF.EXE
- GVFPP[1].HTM
- ISTOD.EXE
- ONCHTJGP.EXE
- OATZJ[1].HTM
- SSOXRUD.EXE
- JYGMBMKU.EXE
- FBVLI.EXE
- E17[1].EXE
- DG1.EXE
- DG2.EXE
- 87104318.EXE
- 45804764.VXE
- 58039987.EXE
Filesizes
The following file size has been seen:
- 61,440 bytes
- 94,208 bytes
- 114,176 bytes
- 111,616 bytes
- 90,112 bytes
File Type
The filename SESK.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.