Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Banking Info Stealer
- System Back Door
- Malicious Software
File Behavior
MU.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Can communicate with other computer systems using HTTP protocols
- Executes a Process
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Adds products to the system registry
- Uses hidden browser windows to connect to web sites without telling you
- Creates system tray popups, messages, errors and security warnings
- Opens browser pop ups
- Runs Javascript code
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Copies files
- Downloads program file(s) and other content from the web
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- Registers a Dynamic Link Library File
- Uses Instant Messaging to communicate without the user's knowledge
- Uses embeded Instant Message Channel Settings
- The Process is polymorphic and can change its structure
- Creates a TCP port which listens and is available for communication initiated by other computers
- Found on infected systems and resists interrogation by security products
MU.EXE has been the subject of the following behavior:
- Executed as a Process
- Deleted as a process from disk
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Added as a Registry auto start to load Program on Boot up
- Copied to multiple locations on the system
- Registered as a Dynamic Link Library File
- Created as a new Background Service on the machine
Country Of Origin
The filename MU.EXE was first seen on Jun 15 2007 in the following geographical regions of the Webroot community:
- Singapore on Jun 15 2007
- Brazil on Jun 15 2007
- Spain on Jan 13 2008
- Vietnam on Jan 13 2008
- India on Nov 8 2009
- Argentina on Nov 8 2009
- Russian Federation on Jul 4 2010
- Germany on Oct 10 2010
- Canada on Oct 10 2010
- Italy on May 20 2012
File Name Aliases
MU.EXE can also use the following file names:
- LP.EXE.EXE
- EU.EXE.EXE
- NI.EXE.EXE
- SUNSHINE MU 0.03.EXE
- MAIN.EXE
- LOADX1[1].EXE
- WMISRPC.EXE
- DPLYRP~1.EXE
- WMIBUSN.EXE
- GY.EXE.EXE
- ZO.EXE.EXE
- MU[1].EXE
- A.EXE
- KU.EXE
- HE.EXE
- AU.EXE
- EE.EXE
- CT.EXE
- XV.EXE
- QR.EXE
- YP.EXE
- MF.EXE
- NU.EXE
- XE.EXE
- PS.EXE
- YE.EXE
- SL.EXE
- KT.EXE
- AF.EXE
- YF.EXE
- AZ.EXE
- KO.EXE
- QK.EXE
- YD.EXE
- TE.EXE
- AP.EXE
- SX.EXE
- MT.EXE
- NC.EXE
- LI.EXE
- XB.EXE
- IS.EXE
- HS.EXE
- IX.EXE
- KC.EXE
- MQ.EXE
- VM.EXE
- HO.EXE
- JK.EXE
- AI.EXE
- ZO.EXE
- ZQ.EXE
- LB.EXE
- AJ.EXE
- VW.EXE
- WK.EXE
- GI.EXE
- IG.EXE
- FB.EXE
- DX.EXE
- CU.EXE
- ZB.EXE
- BD.EXE
- HB.EXE
- QI.EXE
- SS.EXE
- DJ.EXE
- JD.EXE
- NN.EXE
- WZ.EXE
- LS.EXE
- AS.EXE
- GZ.EXE
- YK.EXE
- GC.EXE
- ZD.EXE
- CX.EXE
- YV.EXE
- YY.EXE
- HR.EXE
- RD.EXE
- GX.EXE
- DQ.EXE
- JG.EXE
- EF.EXE
- QT.EXE
- HH.EXE
- TQ.EXE
- AX.EXE
- QC.EXE
- LZ.EXE
- BZ.EXE
- FF.EXE
- ML.EXE
- 52488206.DAT
- 91306982.EXE
- 49593563.DAT
Filesizes
The following file size has been seen:
- 113,664 bytes
- 43,008 bytes
- 286,720 bytes
- 194,048 bytes
- 124,928 bytes
- 2,695,168 bytes
- 2,453,504 bytes
- 694,272 bytes
File Type
The filename MU.EXE refers to many versions of an executable program.
File Activity
One or more files with the name MU.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\dnserrordiagoff_webOC[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\ErrorPageTemplate[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\errorPageStrings[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\httpErrorPagesScripts[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\background_gradient[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\2lcwzf76\info_48[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\7gddxlhz\bullet[1]
- Creates c:\documents and settings\user\local settings\temporary internet files\content.ie5\67acpgmg\down[1]
Website Activity
One or more files with the name MU.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1085 Port:18
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.