Associated Malware Groups
The filename is associated with the malware groups:
File Behavior
84785_REDWORLD[2].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Creates a TCP port which listens and is available for communication initiated by other computers
- Executes a Process
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Registers a Dynamic Link Library File
- Can communicate with other computer systems using HTTP protocols
- Can communicate with other computers using TCP protocols
- Adds products to the system registry
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
84785_REDWORLD[2].EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Created as a new Background Service on the machine
- Deleted as a process from disk
- Terminated as a Process
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
Country Of Origin
The filename 84785_REDWORLD[2].EXE was first seen on Jul 3 2007 in the following geographical regions of the Prevx community:
- Denmark on Jul 3 2007
- Europe on Jul 3 2007
- Spain on Aug 5 2008
- on Aug 5 2008
File Name Aliases
84785_REDWORLD[2].EXE can also use the following file names:
- FREHOST.EXE
- TMP9E.TMP
- RTSECAR.EXE
- 84785_MSSQL[1].EXE
- 84785_REDWORLD[1].EXE
- 84785_MSSQL[2].EXE
- 84785_MSSQL[7].EXE
- 18478_MSSQL[1].EXE
- 84785_REDWORLD[3].EXE
- 84785_MSSQL[3].EXE
- 76728_MSSQL[1].EXE
- 84785_REDWORLD[4].EXE
- 84785_REDWORLD[5].EXE
- 84785_REDWORLD[7].EXE
- 84785_MSSQL[25].EXE
- 84785_MSSQL[28].EXE
- 84785_REDWORLD[35].EXE
- 84785_REDWORLD[17].EXE
- 27031_MSSQL.EXE
- 27031_REDWORLD.EXE
- 84785_REDWORLD[22].EXE
Filesizes
The following file size has been seen:
- 148,480 bytes
- 133,872 bytes
- 111,616 bytes
- 114,688 bytes
File Type
The filename 84785_REDWORLD[2].EXE refers to many versions of an executable program.
File Activity
One or more files with the name 84785_REDWORLD[2].EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\976d_appcompat.txt
- Creates c:\docume~1\user\locals~1\temp\19A08.dmp
- Opens/modifes c:\autoexec.bat
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.