Associated Malware Groups
The filename is associated with the malware groups:
- Malicious Software
- Malware Dropper
File Behavior
RECYCLD.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- Installs a browser helper object (BHO)
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Enables an In Process Object/Server - Common with DLL Injections
- Injects code into other processes
- Registers a Dynamic Link Library File
- Adds products to the system registry
- Creation and Registers a Browser Helper Object in Internet Explorer
- Writes to another Process's Virtual Memory (Process Hijacking)
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- Opens browser pop ups
- The Process is polymorphic and can change its structure
- This Process is a file infector which modifies program files to include a copy of the infection
RECYCLD.EXE has been the subject of the following behavior:
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Deleted as a process from disk
Country Of Origin
The filename RECYCLD.EXE was first seen on Feb 12 2009 in the following geographical regions of the Webroot community:
- The United States on Feb 12 2009
- Canada on Feb 12 2009
- Hong Kong on Feb 25 2009
- Spain on Feb 25 2009
- The United Kingdom on Jul 13 2009
- New Zealand on Feb 28 2010
- Italy on Jun 9 2010
File Name Aliases
RECYCLD.EXE can also use the following file names:
- EXEFILE[n].EXE
- DPLLAW~1.EXE
- 1[1].EXE
- ._BIN_MSUPDATE[n].EXE
- 2.TMP
- C.EXE
- 3.TMP
- E.EXE
- 279E9C~1.EXE
- 73700646.EXE
- 81954634.EXE
Filesizes
The following file size has been seen:
- 65,536 bytes
- 69,120 bytes
- 55,808 bytes
- 55,296 bytes
- 68,608 bytes
- 45,056 bytes
- 89,088 bytes
- 67,584 bytes
- 100,864 bytes
File Type
The filename RECYCLD.EXE refers to many versions of an executable program.
File Activity
One or more files with the name RECYCLD.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\inform.dat
- Creates c:\windows\system32\ak
- Deletes c:\windows\system32\di1.gif
- Deletes c:\windows\system32\dr1.gif
- Deletes c:\windows\system32\cookie1.dat
- Deletes c:\windows\system32\boa1.dat
- Deletes c:\windows\system32\cs.dat
- Deletes c:\windows\system32\ps1.dat
- Deletes c:\windows\system32\rc.dat
- Deletes c:\windows\system32\tb.dr
- Creates c:\windows\system32\ipv6sp.dll
- Deletes c:\8989533.ex
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.