Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Fraudulent Security Program
- Spyware
- Cloaked Malware
- Worm
File Behavior
1.EXE has been seen to perform the following behavior:
- Executes Processes stored in Temporary Folders
- Writes to another Process's Virtual Memory (Process Hijacking)
- This process creates other processes on disk
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- Can communicate with other computer systems using HTTP protocols
- Associated with, or similar to the ZEUS Internet and Online Banking Trojan
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Executes a Process
- Injects code into the operating system function SERVICES.EXE
- Injects code into the operating system function SVCHOST.EXE
- Injects code into the operating system function LSASS.EXE
- Installs a browser helper object (BHO)
- The Process is packed and/or encrypted using a software packing process
- This Process Deletes Other Processes From Disk
- Copies files
- Registers a Dynamic Link Library File
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Adds products to the system registry
1.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Executed from Temporary Folders
- Copied to multiple locations on the system
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Terminated as a Process
Country Of Origin
The filename 1.EXE was first seen on May 18 2007 in the following geographical regions of the Webroot community:
- Australia on May 18 2007
- Canada on May 18 2007
- on May 19 2007
- The United States on May 19 2007
- Spain on Sep 21 2007
- Germany on Jul 18 2008
- The United Kingdom on Dec 24 2009
- Turkey on May 25 2012
File Name Aliases
1.EXE can also use the following file names:
- XBYSFTH.TMP
- SYS1B.EXE
- SYS3.EXE
- SYS1.EXE
- SYS2C9.EXE
- SYS2E.EXE
- SYS5E.EXE
- SYSB9B4.EXE
- SYS7.EXE
- SYSC6.EXE
- SYSF.EXE
- SYS74.EXE
- SYS6C8.EXE
- SYS12.EXE
- SYS83.EXE
- SYS74E.EXE
- SYSE5.EXE
- ANYTOOL.EXE
- E.TMP
- DD4897.EXE
Filesizes
The following file size has been seen:
- 22,016 bytes
- 323,536 bytes
- 65,024 bytes
- 91,136 bytes
- 32,256 bytes
- 373,087 bytes
- 45,056 bytes
- 8,282 bytes
File Type
The filename 1.EXE is used by multiple object types including executable programs,self extracting compressed files,objects.
File Activity
One or more files with the name 1.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\Sys7.tmp
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.