Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malware Dropper
File Behavior
27.TMP has been seen to perform the following behavior:
- Executes a Process
- Registers a Dynamic Link Library File
- This process creates other processes on disk
- Found on infected systems and resists interrogation by security products
- Adds a Registry Key (RUN) to auto start Programs on system start up
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Copies files
- This Process Deletes Other Processes From Disk
27.TMP has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Registered as a Dynamic Link Library File
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Copied to multiple locations on the system
Country Of Origin
The filename 27.TMP was first seen on Mar 16 2008 in the following geographical regions of the Webroot community:
- Canada on Mar 16 2008
- Israel on Mar 29 2008
- Spain on Apr 17 2008
- China on Apr 17 2008
- The United States on Feb 12 2009
- Vietnam on Jan 11 2010
- Italy on Jan 11 2010
- Norway on May 2 2010
- The United Kingdom on May 2 2010
- Turkey on May 16 2012
File Name Aliases
27.TMP can also use the following file names:
- IMPLAYOK.EXE
- SOFT4[1].EXE
- PVUIAIWPN.EXE
- CRYPT16.EXE
- IMAGE10_NOPACK[1].EXE
- NT5C32.EXE
- NT5A32.EXE
- NT5F32.EXE
- NT5B32.EXE
- 5.TMP
- F.TMP
- 8.TMP
- 51.TMP
- 48.TMP
- 25.TMP
- 4C.TMP
- 22.TMP
- 2B.TMP
- 2F.TMP
- 2E.TMP
- NT5732.EXE
- NT5832.EXE
- NT9432.EXE
- NT7132.EXE
- NT5532.EXE
- NT6732.EXE
- NT20632.EXE
- NT24432.EXE
- NT32832.EXE
- NT5632.EXE
- 1EF.TMP
Filesizes
The following file size has been seen:
- 193,018 bytes
- 27,739 bytes
- 516,096 bytes
- 13,824 bytes
- 95,744 bytes
- 7,067 bytes
- 162,532 bytes
- 150,016 bytes
- 39,936 bytes
File Type
The filename 27.TMP is used by multiple object types including executable programs,Dynamic Link LIbraries.
File Activity
One or more files with the name 27.TMP creates, deletes, copies or moves the following files and folders:
- Copies filec:\windows\system32\ws2_32.dll to c:\windows\system32\sockets.dll
- Deletes c:\windows\system32\Crypt_16.dll
- Creates c:\windows\system32\Crypt_16.dll
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.