A589E398.EXE

What you should do about A589E398.EXE:

The most common objects with the name of A589E398.EXE have yet to be classified as safe by our research department.

If you are concerned that your PC might be infected why not try our Free version of Prevx 3.0. It will thoroughly check your PC for millions of active Spyware and malware infections and takes less than 2 minutes. Don't take the risk, check your PC now.

Download Prevx 3.0

What we know about A589E398.EXE:

A589E398.EXE

AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:

DEFINITION OF: A589E398.EXE

  • Safety Rating: Known Malware, do not run
  • Malware Family: Part of Malware group - Polynomial Code Exploit
  • Determination: Automatically determined using Prevx centralized heuristics
  • Malware Form: EXPLOIT
  • Protection: Prevx provides powerful security products that you can use to detect, remove and protect you from A589E398.EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
  • Why risk having spyware on your PC when it takes less than 2 minutes to thoroughly check it with Prevx CSI? Click here to check your PC with Prevx CSI Now.
  • First seen: Sep 15 2008 (GMT)
  • Last seen: Sep 15 2008 (GMT)
  • File Size: 38,912 bytes
MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY

1. COVERT ANALYSIS OF: A589E398.EXE

  • File Names Used: 41
  • Paths Used: 1
  • Common File Name: A589E398.EXE
  • Common Path: %WINDIR%\TEMP\
  • Vendor Information: No Vendor details specified
  • A589E398.EXE may use 41 or more path and file names, these are the most common:
  • 1 :%WINDIR%\TEMP\0D646AEC.EXE
  • 2 :%WINDIR%\TEMP\11125795.EXE
  • 3 :%WINDIR%\TEMP\1209978B.EXE
  • 4 :%WINDIR%\TEMP\1453190F.EXE
  • 5 :%WINDIR%\TEMP\223C4754.EXE
  • 6 :%WINDIR%\TEMP\2760937D.EXE
  • 7 :%WINDIR%\TEMP\28085BB7.EXE
  • 8 :%WINDIR%\TEMP\2A6D2611.EXE
  • 9 :%WINDIR%\TEMP\33E35BF0.EXE
  • 10:%WINDIR%\TEMP\44CEE574.EXE
  • 11:%WINDIR%\TEMP\50E3F4AA.EXE
  • 12:%WINDIR%\TEMP\6614E64D.EXE
  • 13:%WINDIR%\TEMP\67202B29.EXE
  • 14:%WINDIR%\TEMP\860A2658.EXE
  • 15:%WINDIR%\TEMP\87887AB7.EXE
  • File Name Structure: Normal
  • File and Path Structure: Suspicious, unusually high number of file and path combinations

2. RELATIONSHIP ANALYSIS OF: A589E398.EXE

  • No relationship details available for this object

3. ACTIVITY ANALYSIS OF: A589E398.EXE

  • The following behaviors have been observed for this object:
  • Communicates with web sites using httpout protocols.
  • Hijacks running processes.

4. PROPAGATION ANALYSIS OF: A589E398.EXE

  • Malware Group Propagation Rate: Moderate (spreading)
  • Malware Group: Polynomial Code Exploit
  • Copyright Prevx Limited 2005, 2006

Copyright Prevx Ltd
Page Generated on Mar 21, 2010 13:52