Associated Malware Groups
The filename is associated with the malware groups:
- Malicious Software
- Malware Dropper
File Behavior
RECYCLD.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- Installs a browser helper object (BHO)
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Enables an In Process Object/Server - Common with DLL Injections
- Injects code into other processes
- Registers a Dynamic Link Library File
- Adds products to the system registry
- Creation and Registration of a Browser Helper Object in Internet Explorer
- Writes to another Process's Virtual Memory (Process Hijacking)
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- Opens browser pop ups
- The Process is polymorphic and can change its structure
RECYCLD.EXE has been the subject of the following behavior:
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Deleted as a process from disk
Country Of Origin
The filename RECYCLD.EXE was first seen on Feb 15 2009 in the following geographical regions of the Prevx community:
- The United Kingdom on Feb 15 2009
- Spain on Feb 15 2009
- Hong Kong on Feb 25 2009
- The United States on Jul 13 2009
- New Zealand on Feb 28 2010
- Italy on Mar 16 2010
File Name Aliases
RECYCLD.EXE can also use the following file names:
- EXEFILE[n].EXE
- DPLLAW~1.EXE
- 1[1].EXE
- 2.TMP
- C.EXE
- 3.TMP
- E.EXE
- 73700646.EXE
- 81954634.EXE
Filesizes
The following file size has been seen:
- 65,536 bytes
- 69,120 bytes
- 55,808 bytes
- 55,296 bytes
- 89,088 bytes
- 100,864 bytes
- 44,032 bytes
File Type
The filename RECYCLD.EXE refers to many versions of an executable program.
File Activity
One or more files with the name RECYCLD.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\inform.dat
- Creates c:\windows\system32\ak
- Deletes c:\windows\system32\di1.gif
- Deletes c:\windows\system32\dr1.gif
- Deletes c:\windows\system32\cookie1.dat
- Deletes c:\windows\system32\boa1.dat
- Deletes c:\windows\system32\cs.dat
- Deletes c:\windows\system32\ps1.dat
- Deletes c:\windows\system32\rc.dat
- Deletes c:\windows\system32\tb.dr
- Creates c:\windows\system32\ipv6sp.dll
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.