Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
COMP.EXE has been seen to perform the following behavior:
- Copies files
- This Process is a file infector which modifies program files to include a copy of the infection
- Executes a Process
- Looks at the contents of the autoexec.bat file
- Drops known malicious software during execution
- Opens browser pop ups
- The Process is packed and/or encrypted using a software packing process
COMP.EXE has been the subject of the following behavior:
- Created as a process on disk
- Deleted as a process from disk
- Executed as a Process
- Added as a Registry auto start to load Program on Boot up
Country Of Origin
The filename COMP.EXE was first seen on Sep 15 2007 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Sep 15 2007
- The UNITED STATES on Sep 25 2007
- SPAIN on Apr 23 2009
- The UNITED KINGDOM on Apr 23 2009
Filesizes
The following file size has been seen:
- 15,872 bytes
- 645,632 bytes
- 162,304 bytes
- 40,448 bytes
- 27,136 bytes
- 8,704 bytes
File Type
The filename COMP.EXE is used by multiple object types including objects,objects.
File Activity
One or more files with the name COMP.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\magnify.ivr
- Copies filec:\windows\system32\magnify.ivr to c:\windows\system32\magnify.exe
- Deletes c:\windows\system32\magnify.ivr
- Creates c:\windows\system32\narrator.ivr
- Copies filec:\windows\system32\narrator.ivr to c:\windows\system32\narrator.exe
- Deletes c:\windows\system32\narrator.ivr
- Creates c:\windows\system32\osk.ivr
- Copies filec:\windows\system32\osk.ivr to c:\windows\system32\osk.exe
- Deletes c:\windows\system32\osk.ivr
- Creates c:\windows\system32\utilman.ivr
- Copies filec:\windows\system32\utilman.ivr to c:\windows\system32\utilman.exe
- Deletes c:\windows\system32\utilman.ivr
- Creates c:\program files\outlook express\wab.ivr
- Copies filec:\program files\outlook express\wab.ivr to c:\program files\outlook express\wab.exe
- Deletes c:\program files\outlook express\wab.ivr
- Creates c:\program files\windows media player\wmplayer.ivr
- Copies filec:\program files\windows media player\wmplayer.ivr to c:\program files\windows media player\wmplayer.exe
- Deletes c:\program files\windows media player\wmplayer.ivr
- Creates c:\windows\system32\notepad.ivr
- Copies filec:\windows\system32\notepad.ivr to c:\windows\system32\notepad.exe
- Deletes c:\windows\system32\notepad.ivr
- Creates c:\windows\system32\mobsync.ivr
- Copies filec:\windows\system32\mobsync.ivr to c:\windows\system32\mobsync.exe
- Deletes c:\windows\system32\mobsync.ivr
- Creates c:\windows\system32\tourstart.ivr
- Copies filec:\windows\system32\tourstart.ivr to c:\windows\system32\tourstart.exe
- Deletes c:\windows\system32\tourstart.ivr
- Creates c:\windows\system32\rcimlby.ivr
- Copies filec:\windows\system32\rcimlby.ivr to c:\windows\system32\rcimlby.exe
- Deletes c:\windows\system32\rcimlby.ivr
- Deletes c:\documents and settings\jim\cookies\index.dat
- Deletes c:\documents and settings\jim\cookies\jim@adobe[1].txt
- Deletes c:\documents and settings\jim\cookies\jim@auto.sea
- Deletes c:\documents and settings\jim\cookies\jim@c.msn
- Deletes c:\documents and settings\jim\cookies\jim@doubleclick[1].txt
- Deletes c:\documents and settings\jim\cookies\jim@download.moz
- Deletes c:\documents and settings\jim\cookies\jim@genuine[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@google[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@live[1].txt
- Deletes c:\documents and settings\jim\cookies\jim@m.web
- Deletes c:\documents and settings\jim\cookies\jim@microsoftwga.112
- Deletes c:\documents and settings\jim\cookies\jim@microsoft[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@mozilla[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@msn[1].txt
- Deletes c:\documents and settings\jim\cookies\jim@search.liv
- Deletes c:\documents and settings\jim\cookies\jim@search.msn
- Deletes c:\documents and settings\jim\cookies\jim@snapfiles[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@sourceforge[2].txt
- Deletes c:\documents and settings\jim\cookies\jim@tt11.ado
- Deletes c:\documents and settings\jim\cookies\jim@winkeyfinder[2].txt
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.