PLAY_MP3[1]..EXE
AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:
DEFINITION OF: PLAY_MP3[1]..EXE
* Safety Rating: Known malware, do not run
* Determination: Automatically determined using Prevx centralized heuristics
* Protection: Prevx provides powerful security products that you can use to detect, remove and protect you from PLAY_MP3[1]..EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
* Why risk having spyware on your PC when it takes less than 2 minutes to thoroughly check it with Prevx CSI? Click here to check your PC with Prevx CSI Now.
* First seen: Mar 14 2007 (GMT)
* Last seen: Mar 14 2007 (GMT)
* File Size: 208,159 bytes
MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY
1. COVERT ANALYSIS OF: PLAY_MP3[1]..EXE
* File Names Used: 220
* Paths Used: 56
* Common File Name: PLAY_MP3[1]..EXE
* Common Path: %TEMP%\
* Vendor Information: No Vendor details specified
* Product Information: Installer
* Version Information: 1.0.0.1
* PLAY_MP3[1]..EXE may use 220 or more path and file names, these are the most common:
* 1 :%CACHE%\CONTENT.IE5\????????\PLAY[1].EXE
* 2 :%CACHE%\CONTENT.IE5\????????\PLAY_MP3[1]..EXE
* 3 :%CACHE%\CONTENT.IE5\????????\PLAY_MP3[2].EXE
* 4 :%CACHE%\CONTENT.IE5\????????\PLAY_MP3[3].EXE
* 5 :%CACHE%\CONTENT.IE5\????????\PLAY_MP3[4].EXE
* 6 :%DESKTOP%\PLAY_MP3(2).EXE
* 7 :%DESKTOP%\PLAY_MP3.EXE
* 8 :%documents%\my completed downloads\44-371-O6S6MR76Q56OSQA6PLNGM.....EXE
* 9 :%DOCUMENTS%\MY PICTURES\PLAY_MP3.EXE
* 10:%DOCUMENTS%\PUSZINYUSZI.EXE
* 11:%TEMP%\1SZY9MLZ.EXE
* 12:%TEMP%\299NZSE5.EXE
* 13:%TEMP%\4GAK46QV.EXE
* 14:%TEMP%\9JLWPUZA.EXE
* 15:%TEMP%\BBNTQCBW.EXE
* File Name Structure: Normal
* File and Path Structure: Suspicious, code execution from unusual location
2. RELATIONSHIP ANALYSIS OF: PLAY_MP3[1]..EXE
* Malicious Objects Created: 1 objects
* Malicious Creators: None
* Malware Run Keys: None
* Self Persists:
* Antivirus Detection: No third party antivirus detection observed
* Anti-Spyware Detection: No third party anti-spyware detection observed
3. ACTIVITY ANALYSIS OF: PLAY_MP3[1]..EXE
* The following behaviors have been observed for this object:
* Installs programs.
* Runs temporary programs.
* Runs other programs.
* Communicates with web sites using httpout protocols.
* Hijacks running processes.
* Creates known malware.
4. PROPAGATION ANALYSIS OF: PLAY_MP3[1]..EXE
* Object Propagation Rate: Very Low (minimal spread)