Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
RAR.V3.80.BETA.3.LINUX/SETUP.EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- Creates system tray popups, messages, errors and security warnings
- Can communicate with other computer systems using HTTP protocols
- Changes the Internet Explorer Home Page Settings
- Changes the Internet Explorer Search Page
- Terminates Processes
- Executes Processes stored in Temporary Folders
- This Process Deletes Other Processes From Disk
- Adds new menu items in the Internet Explorer Right Click menu
- Adds products to the system registry
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Enables an In Process Object/Server - Common with DLL Injections
- Executes a Process
RAR.V3.80.BETA.3.LINUX/SETUP.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Terminated as a Process
- Has code inserted into its Virtual Memory space by other programs
Country Of Origin
The filename RAR.V3.80.BETA.3.LINUX/SETUP.EXE was first seen on Jul 8 2008 in the following geographical regions of the Prevx community:
- SPAIN on Jul 8 2008
- BRAZIL on Jul 8 2008
File Name Aliases
RAR.V3.80.BETA.3.LINUX/SETUP.EXE can also use the following file names:
- NETPUMPER-1.50-SETUP.EXE
- 26412498.EXE
- 97756719.EXE
- 00864995.EXE
- 19102253.EXE
- 49214982.DAT
- NETPUMPER-1.50-SETUP[n].EXE
- DG133.EXE
- 41978628.SVD
- 61945849.EXE
- 09687625.EXE
- 36678153.EXE
- VLJ7FU7A.EXE
- AZ.AVI.MPEG.MOV.RM.WMV.IPOD.MP4.CONVERTER.V7.29-YPOGEIOS/SETUP.EXE
- NIK.SOFTWARE.SILVER.EFEX.PRO.V1.0.INCL.KEYGEN-VIRILITY/SETUP.EXE
- CHECKPOINT.ZONEALARM.INTERNET.SECURITY.SUITE.V7.0.483.000.INCL.KEYMAKER-ZWT/SETUP.EXE
- WEBROOT SPY SWEEPER V5.8.1.47/SETUP.EXE
- SETUP.EXE
- SLYSOFT.ANYDVD.HD.V6.4.5.5.MULTILINGUAL.WINALL.INCL.KEYGEN.AND.PATCH-BRD/SETUP.EXE
- PERSONAL.FINANCES.PRO.3.1.READ.NFO.CRACKED.EXE-REV/SETUP.EXE
- ACTIVESTATE.KOMODO.IDE.V4.4.1.20896.FOR.WINDOWS-BEAN/SETUP.EXE
- GLOBAL.MAPPER.V10.0.10.0_1000TH.RELEASE-NOPE/SETUP.EXE
- MINITAB.V15.1.20.KEYMAKER.ONLY-CORE/SETUP.EXE
- WYSIWYG.WEB.BUILDER.5.5.2.KEYGEN-SND/SETUP.EXE
- MAGIX.SAMPLITUDE.V10.1-RECOIL/SETUP.EXE
- CHMEDITOR.V1.2.BUILD.059.CRACKED/SETUP.EXE
- SWISH.MAX.2.0.2008.8.12-LZ0/SETUP.EXE
- FINEPRINT.V6.01.INCL.KEYMAKER-ZWT/SETUP.EXE
- 31179944.EXE
- 57943616.DAT
- 05136052.EXE
- 90904435.EXE
Filesizes
The following file size has been seen:
- 491,440 bytes
- 276,704 bytes
- 276,648 bytes
- 276,608 bytes
- 276,448 bytes
- 491,488 bytes
File Type
The filename RAR.V3.80.BETA.3.LINUX/SETUP.EXE refers to many versions of an executable program.
File Activity
One or more files with the name RAR.V3.80.BETA.3.LINUX/SETUP.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\docume~1\user\locals~1\temp\nsk8.tmp
- Creates c:\docume~1\user\locals~1\temp\nsaA.tmp
- Deletes c:\docume~1\user\locals~1\temp\nsqC.tmp
- Creates c:\docume~1\user\locals~1\temp\nsqc.tmp\nsProcess.dll
- Creates c:\docume~1\user\locals~1\temp\nsqc.tmp\ioSpecial.ini
- Creates c:\docume~1\user\locals~1\temp\nsqc.tmp\modern-wizard.bmp
- Creates c:\docume~1\user\locals~1\temp\nsqc.tmp\modern-header.bmp
- Creates c:\docume~1\user\locals~1\temp\nsqc.tmp\InstallOptions.dll
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.