Sus.Behav

By GoldSparrow in Malware

Sus.Behav is a malware that installs itself onto a computer under deceptive pretences, infiltrating a system without user knowledge or permission. Officially categorized as a file, displaying suspicious behavior, Sus.Behav should not be trusted. Sus.Behav may typically be downloaded unknowingly from malicious websites, freeware and shareware, and peer-to-peer networks. Sus.Behav can cause registry files to go missing, corrupt files to re-open after being erased, unwanted web browser components, changes in Internet settings and decreased system speeds.

File System Details

Sus.Behav may create the following file(s):
# File Name Detections
1. EntriqMediaServer.exe
2. opnonkhe.dll
3. FGSHEL~1.DLL
4. CarboniteSetupLitePBPreInstaller.exe
5. fpfstb.dll
6. DWRCS.EXE
7. alt.exe.exe
8. cbXPiFwT.dll
9. ERCUtil.dll
10. ccleaner.exe
11. CarbonitePreinstaller.exe
12. xfire.exe
13. SpySweeperUI.exe
14. tuvVLcay.dll
15. rqRiiHXQ.dll
16. av2009.exe
17. tbaction.exe
18. __c00135A8.dat

Registry Details

Sus.Behav may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\opnonkhe
RUNNING PROGRAM\EXPLORER.EXE
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 29247207685934936530823877733220
RUNNING PROGRAM\DWRCS.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ TBAction
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PromoReg
RUNNING PROGRAM\winlogon.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ CarboniteSetupLite
RUNNING PROGRAM\xfire.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\ AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SpySweeper
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\tuvVLcay
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__c00135A8
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ccleaner
RUNNING PROGRAM\EntriqMediaServer.exe

Trending

Most Viewed

Loading...