Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
ZIP.DLL has been seen to perform the following behavior:
- Enables an In Process Object/Server - Common with DLL Injections
- Adds a Registry Key (DELAY) to auto start Programs on system start up
- The Process is packed and/or encrypted using a software packing process
- Executes a Dynamic Link Library File as a process
- Can communicate with other computer systems using HTTP protocols
- This Process Deletes Other Processes From Disk
ZIP.DLL has been the subject of the following behavior:
- Enabled as an In Process Object/Server - Common with DLL Injections
- Added as a Registry Key (DELAY) to auto start Programs on system start up
- Created as a process on disk
- Executed as a process
- Deleted as a process from disk
- Registered as a Dynamic Link Library File
- Executed as a Process
Country Of Origin
The filename ZIP.DLL was first seen on May 31 2007 in the following geographical regions of the Prevx community:
- Belgium on May 31 2007
- Russian Federation on May 31 2007
- The United States on Jun 1 2007
- Saudi Arabia on Jun 1 2007
- Korea, Republic of on Aug 23 2007
- Italy on Aug 23 2007
- Georgia on Oct 15 2007
- Spain on Nov 23 2007
- Canada on Feb 26 2008
- Netherlands on Mar 22 2010
File Name Aliases
ZIP.DLL can also use the following file names:
Filesizes
The following file size has been seen:
- 39,462 bytes
- 47,104 bytes
- 40,960 bytes
- 31,232 bytes
- 28,672 bytes
- 102,400 bytes
- 39,424 bytes
- 38,950 bytes
File Type
The filename ZIP.DLL refers to many versions of a dynamic link library.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.