Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Malicious Software
- Malware Downloader
- Malware Dropper
File Behavior
INFO.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- This process creates other processes on disk
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This Process Deletes Other Processes From Disk
- Deletes Links in the Start Menu
- Adds a Link in the Start Menu
- Registers a Dynamic Link Library File
- Modifies Windows Initialization And System Settings Used On Start up
- Modifies the User Shell objects used to run code from other processes
- Enables the system to use a Communications Proxy Server
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Injects code into other processes
- Copies files
- Uses Instant Messaging to communicate without the user's knowledge
- Uses embeded Instant Message Channel Settings
INFO.EXE has been the subject of the following behavior:
- Created as a new Background Service on the machine
- Created as a process on disk
- Executed by Internet Explorer
- Executed as a Process
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Deleted as a Link in the Start Menu
- Added as a Link in the Start Menu
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Copied to multiple locations on the system
Country Of Origin
The filename INFO.EXE was first seen on May 18 2007 in the following geographical regions of the Prevx community:
- The United States on May 18 2007
- on May 18 2007
- Spain on Sep 3 2007
- Netherlands on Sep 3 2007
- Mexico on Dec 14 2009
- The United Kingdom on Mar 17 2010
File Name Aliases
INFO.EXE can also use the following file names:
- HARDDISKVOLUME3EXE.EXE
- ICF.EXE
- WINFCAM.EXE
- CSI639.TMP
- INFO.0XE
- WINLYPB.EXE
- WINLIXX.EXE
- EXPLORE.EXE
- EXPLORE 2.EXE
- BACKUP-20070923-124947-359-INFO.EXE
- BACKUP-20070923-124947-843-INFO.EXE
- EXPLOEEE.EXE
- EXPLORE(2).EXE
- SVCHOST.EXE:EXE.EXE
- INFO-E7BA5C8B__REPEAT_.EXE
- DISKINFO.EXE
- DRIVES.EXE
- DXCONSOLE.EXE
- __DELETE_ON_REBOOT__E_X_P_L_O_R_E_._E_X_E_
- INFO.VEXE
- DC11.EXE
- DC9.EXE
- DC235.EXE
- DC31.EXE
- DC33.EXE
- INFO.EXECOMMON STARTUP
- INFO.EXESTARTUP
- EXP
- 92417208.SVD
- 08891658.EXE
Filesizes
The following file size has been seen:
- 33,819 bytes
- 24,064 bytes
- 9,728 bytes
- 24,576 bytes
- 117,312 bytes
- 94,208 bytes
File Type
The filename INFO.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.