Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
CAKEMANIA3.EXE has been seen to perform the following behavior:
- Enables an In Process Object/Server - Common with DLL Injections
- Executes a Process
- This process creates other processes on disk
- This Process is a file infector which modifies program files to include a copy of the infection
- Opens browser pop ups
- Runs Javascript code
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Terminates Processes
- Can communicate with other computer systems using HTTP protocols
- Uses DNS to retrieve the IP address for web sites
CAKEMANIA3.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename CAKEMANIA3.EXE was first seen on Aug 31 2008 in the following geographical regions of the Prevx community:
- The United States on Aug 31 2008
- Czech Republic on Oct 6 2008
- Norway on Nov 15 2008
- Spain on Apr 26 2009
File Name Aliases
CAKEMANIA3.EXE can also use the following file names:
- DEVICE
- 16966203.SVD
- 35072625.TXT
- 18404264.TXT
Filesizes
The following file size has been seen:
- 1,769,472 bytes
- 774,144 bytes
- 3,694,592 bytes
- 3,329,384 bytes
- 620,207 bytes
File Type
The filename CAKEMANIA3.EXE refers to many versions of an executable program.
File Activity
One or more files with the name CAKEMANIA3.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\jim\locals~1\temp\ixp000.tmp\TMP4351$.TMP
- Creates c:\docume~1\jim\locals~1\temp\ixp000.tmp\settings.exe
- Creates c:\docume~1\jim\locals~1\temp\ixp000.tmp\CakeMania3.exe
- Deletes c:\docume~1\jim\locals~1\temp\ixp000.tmp\CakeMania3.exe
- Deletes c:\docume~1\jim\locals~1\temp\ixp000.tmp\settings.exe
- Opens/modifes c:\autoexec.bat
Network Activity
One or more files with the name CAKEMANIA3.EXE performs the following network events:
- DNS Lookup127.0.0.1 0
- DNS Lookup91.121.111.205 91.121.111.205
Website Activity
One or more files with the name CAKEMANIA3.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1053 Port:17
- Port 80 IP:91.121.111.205
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.