Disagree with this determination?
File Behavior
22531721.COM has been seen to perform the following behavior:
- Uses hidden browser windows to connect to web sites without telling you
- Creates system tray popups, messages, errors and security warnings
- Opens browser pop ups
- Runs Javascript code
- Uses DNS to retrieve the IP address for web sites
22531721.COM has been the subject of the following behavior:
Country Of Origin
The filename 22531721.COM was first seen on Apr 9 2009 in the following geographical region of the Prevx community:
File Name Aliases
22531721.COM can also use the following file names:
- 25197211.COM
- 25808974.TXT
- 93470041.EXE
Filesizes
This file has been seen with the following file size:
Vendor, Product and Version Information
A file with the name 22531721.COM have been seen to have the following Vendor, Product and Version Information in the file header:
File Type
The filename 22531721.COM refers to an executable program.
File Activity
One or more files with the name 22531721.COM creates, deletes, copies or moves the following files and folders:
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\dnserrordiagoff_webOC[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\d8p6qalb\dnserrordiagoff_webOC[1
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\ErrorPageTemplate[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\errorPageStrings[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\p1sfj0cw\ErrorPageTemplate[1
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\errorPageStrings[2]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\httpErrorPagesScripts[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\khedh26t\background_gradient[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\d8p6qalb\info_48[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\mgfcz291\bullet[1]
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\p1sfj0cw\down[1]
- Opens/modifes c:\autoexec.bat
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\khedh26t\dnserrordiagoff_webOC[1
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\d8p6qalb\ErrorPageTemplate[1
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\p1sfj0cw\dnserrordiagoff_webOC[1
- Creates c:\documents and settings\jim\local settings\temporary internet files\content.ie5\khedh26t\ErrorPageTemplate[1
Registry Activity
One or more files with the name 22531721.COM creates or modifies the following registry keys and values:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Resource C:\WINDOWS\csrss.exe
Network Activity
One or more files with the name 22531721.COM performs the following network events:
- DNS Lookup127.0.0.1 0
- DNS Lookup foro.remoteexecution.com
Website Activity
One or more files with the name 22531721.COM interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1057 Port:19