Associated Malware Groups
The filename is associated with the malware group:
File Behavior
SYSMGR.EXE has been seen to perform the following behavior:
- Sends mail without telling you
- Creates a new Background Service on the machine
- Uses your PC to connect to Chat rooms
- Sends email using SMTP protocols
- Executes a Process
- Found on infected systems and resists interrogation by security products
- This process creates other processes on disk
- Registers Start Of Authority configuration settings for email servers
SYSMGR.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Changes to the file command map within the registry
- Created as a process on disk
- Executed as a Process
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
Country Of Origin
The filename SYSMGR.EXE was first seen on Aug 27 2009 in the following geographical regions of the Prevx community:
- Spain on Aug 27 2009
- Europe on Aug 27 2009
File Name Aliases
SYSMGR.EXE can also use the following file names:
- MSRXP[n].EXE
- 77613333.EXE
- DS.EXE
- DPLRNKLLUV-340.PMS.EXE
- P.EXE
- DGS.EXE
- H0.EXE
- O1.EXE
- LO.EXE
- A0A.EXE
- K0.EXE
Filesizes
This file has been seen with the following file size:
Vendor, Product and Version Information
This file has no vendor, product or version information specified in the file header.
File Type
The filename SYSMGR.EXE refers to an executable program.
File Activity
One or more files with the name SYSMGR.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\msvcrt2.dll
- Creates c:\windows\system32\sysmgr.exe
Registry Activity
One or more files with the name SYSMGR.EXE creates or modifies the following registry keys and values:
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters TcpTimedWaitDelay [REG_DWORD, value: 0000001E]
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters MaxUserPort [REG_DWORD, value: 00008000]
Network Activity
One or more files with the name SYSMGR.EXE performs the following network events:
Website Activity
One or more files with the name SYSMGR.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:10.10.66.1:53 Port:12
- TCP:10.10.66.1:53 Port:13
- TCP:78.159.102.117:921 Port:12
- TCP:65.55.92.184:25 Port:13
- TCP:208.213.192.139:25 Port:13
- TCP:98.137.54.237:25 Port:13
- TCP:168.95.5.23:25 Port:13
- TCP:205.188.109.56:25 Port:14
- TCP:65.55.92.136:25 Port:14
- TCP:206.46.232.11:25 Port:14
- TCP:67.99.47.210:25 Port:14
- TCP:151.151.5.57:25 Port:14
- TCP:170.49.43.83:25 Port:14
- TCP:202.137.234.30:25 Port:14
- TCP:66.135.195.180:25 Port:15
- TCP:65.55.92.168:25 Port:15
- TCP:65.55.37.72:25 Port:15
- TCP:208.80.204.253:25 Port:15
- TCP:166.102.165.121:25 Port:15
- TCP:146.145.93.2:25 Port:16
- TCP:207.97.230.69:25 Port:16
- TCP:216.39.53.1:25 Port:16
- TCP:66.196.97.250:25 Port:16
- TCP:209.64.143.115:25 Port:16
- TCP:216.70.20.241:25 Port:16
- TCP:70.155.169.68:25 Port:16
- TCP:24.233.167.172:25 Port:16
- TCP:168.95.5.9:25 Port:16
- TCP:203.200.235.141:25 Port:17
- TCP:216.163.188.54:25 Port:17
- TCP:64.18.7.11:25 Port:17
- TCP:209.181.247.105:25 Port:17
- TCP:217.75.128.7:25 Port:17
- TCP:168.95.5.8:25 Port:17
- TCP:220.181.12.81:25 Port:17
- TCP:64.18.6.11:25 Port:18
- TCP:207.69.189.219:25 Port:18
- TCP:192.85.154.101:25 Port:17
- TCP:81.174.66.26:25 Port:17
- TCP:206.190.53.191:25 Port:18
- TCP:64.18.7.10:25 Port:18
- TCP:145.247.25.7:25 Port:16
Help the Prevx Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.