Associated Malware Groups
The filename is associated with the malware groups:
- System Back Door
- Cloaked Malware
File Behavior
TEMFLASH[1].EXE has been seen to perform the following behavior:
- Executes a Process
- Disables the built in Windows File Protection System
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes Processes stored in Temporary Folders
- This Process Deletes Other Processes From Disk
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Injects code into other processes
- Registers a Dynamic Link Library File
- Sends email using SMTP protocols
TEMFLASH[1].EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Executed from Temporary Folders
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Added as a Registry Key (RUNONCE) to auto start Programs on system start up
Country Of Origin
The filename TEMFLASH[1].EXE was first seen on Feb 6 2010 in the following geographical regions of the Prevx community:
- Philippines on Feb 6 2010
- Korea, Republic of on Feb 6 2010
- Brazil on Feb 7 2010
- India on Mar 13 2010
- The United Kingdom on Mar 13 2010
File Name Aliases
TEMFLASH[1].EXE can also use the following file names:
Filesizes
The following file size has been seen:
- 61,440 bytes
- 28,672 bytes
- 3,584 bytes
- 61,952 bytes
- 79,360 bytes
File Type
The filename TEMFLASH[1].EXE is used by multiple object types including objects,Dynamic Link LIbraries,executable programs.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.