Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malware Downloader
File Behavior
IEUPDATER[1].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Registers a Dynamic Link Library File
- Can communicate with other computer systems using HTTP protocols
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Downloads hidden code from covert web sites
- Creates a new Background Service on the machine
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
IEUPDATER[1].EXE has been the subject of the following behavior:
- Deleted as a process from disk
- Executed by Internet Explorer
- Executed as a Process
- Created as a new Background Service on the machine
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename IEUPDATER[1].EXE was first seen on Nov 5 2007 in the following geographical regions of the Prevx community:
- The United States on Nov 5 2007
- Spain on Nov 23 2007
- Canada on Nov 23 2007
- Germany on Apr 17 2008
- Russian Federation on Sep 15 2008
File Name Aliases
IEUPDATER[1].EXE can also use the following file names:
- IEUPDR2.EXE
- IE_UPDATES3R.EXE
- IEUPDATER[2].EXE
- IEUPDATER[3].EXE
- WINLAGAN.EXE
- IE_UPDATER.EXE
- IEUPDR.EXE
- AAAAA_4B69271D1E1F3B83894460533881AFB9.EXE
- ~.EXE
- 0.EXE
- 007218-166FF3F1.EXE
- _SVCHOST.EXE__DELETE_ON_REBOOT
- _SVCHOST.EXE
- 57917673.DAT
Filesizes
The following file size has been seen:
- 6,144 bytes
- 700 bytes
- 20,200 bytes
- 3,009 bytes
- 3,013 bytes
- 3,221 bytes
File Type
The filename IEUPDATER[1].EXE refers to many versions of an executable program.
File Activity
One or more files with the name IEUPDATER[1].EXE creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
- Creates c:\windows\temp\parC9FA.tmp
- Creates c:\documents and settings\all users\documents\t
- Deletes c:\documents and settings\all users\documents\t
- Deletes c:\documents and settings\all users\documents\settings\partnership.dll
- Moves c:\windows\temp\parC9FA.tmp to c:\documents and settings\all users\documents\settings\partnership.dll
- Creates c:\windows\temp\par2FF0.tmp
- Deletes c:\windows\temp\par2FF0.tmp
- Creates c:\windows\temp\par4D3D.tmp
- Deletes c:\windows\temp\par4D3D.tmp
- Creates c:\windows\temp\parAB8.tmp
- Deletes c:\windows\temp\parAB8.tmp
- Creates c:\windows\temp\par8723.tmp
- Creates c:\windows\system32\svcp.csv
- Creates c:\windows\system32\coco.exe
- Creates c:\windows\system32\alt12.exe
- Creates c:\windows\system32\kr_done1
- Copies filec:\windows\system32\coco.exe to c:\windows\kavir.exe
- Creates c:\windows\nivavir.con
Network Activity
One or more files with the name IEUPDATER[1].EXE performs the following network events:
- DNS Lookup69.41.164.187 mssystem.info
Website Activity
One or more files with the name IEUPDATER[1].EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1103 Port:16
- Port 80 IP:58.65.239.115
- TCP:127.0.0.1:1101 Port:14
- Port 80 IP:58.65.239.42
- Port 80 IP:69.41.164.187
- TCP:0.0.0.0:25 Port:13
- TCP:66.235.186.220:15654 Port:13
- Port 80 IP:69.41.185.66
- TCP:64.233.185.114:25 Port:17
- Port 80 IP:195.93.218.56
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.