Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- System Back Door
- Cloaked Malware
- Malware Downloader
File Behavior
ICTHIS.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- Modifies System Runtime Policies to limit system usability
- This process creates other processes on disk
- Registers a Dynamic Link Library File
- Makes outbound connections to other computers using NETBIOSOUT protocols
- This Process Deletes Other Processes From Disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds products to the system registry
- Can communicate with other computer systems using HTTP protocols
- Executes Processes stored in Temporary Folders
- Terminates Processes
- Changes the Internet Explorer Home Page Settings
ICTHIS.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Terminated as a Process
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename ICTHIS.EXE was first seen on Sep 25 2007 in the following geographical regions of the Webroot community:
- The United States on Sep 25 2007
- Netherlands on Sep 25 2007
- Europe on Sep 26 2007
- Germany on Nov 3 2007
- Belgium on Nov 3 2007
- Canada on Nov 14 2007
File Name Aliases
ICTHIS.EXE can also use the following file names:
- GO AWAY.EXE
- ONLINE VIDEO ADD-ON/ICTHIS.EXE
- IMAGE ADD-ON/ICTHIS.EXE
- ICTHIS.EXE__DELETE_ON_REBOOT_TOBEDELETED_OLD_TOBEDELETED_OLD
- ICTHIS.EXE__DELETE_ON_REBOOT
- ICTHIS.EXE__DELETE_ON_REBOOT_TOBEDELETED_OLD
Filesizes
The following file size has been seen:
- 31,744 bytes
- 26,112 bytes
- 30,208 bytes
- 26,770 bytes
- 34,304 bytes
- 25,088 bytes
File Type
The filename ICTHIS.EXE refers to many versions of an executable program.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.