File Search: 

ThreatExpert's awareness of the file "7.exe":

Across all ThreatExpert reports, the file "7.exe" was mostly identified as a threat.
File "7.exe" has the following statistics:
Total number of reports analysed611,932
Number of cases that involved the file "7.exe"319
Number of incidents when this file was found to be a threat256
Statistical volume of cases when "7.exe" was a threat80%
Please enable javascript to display the chart.
Notes:
  • Please note that the name of the file should NOT be used to define if it is legitimate or not. Such determination can only be made by observing its dynamic behaviour.
  • In order to check a file, please submit it to ThreatExpert.
  • For a comprehensive pro-active protection against threats, please consider ThreatFire - our behavioral antivirus solution.
The file "7.exe" is known to be created under the following filenames:
%AllUsersProfile%\cncdown.exe
%AppData%\1.exe
%AppData%\blaah.exe
%AppData%\calc.exe
%AppData%\codecsetup.exe
%AppData%\codecsetup3788.exe
%AppData%\codecsetup4127.exe
%AppData%\codecsetup6400.exe
%AppData%\codecsetup8536.exe
%AppData%\cp_setup_assist.exe
%AppData%\cuda.exe
%AppData%\dealassistant\dauninstall.exe
%AppData%\digifast\dfuninstall.exe
%AppData%\hose.exe
%AppData%\ijango_toolbar_installer.exe
%AppData%\ldr.exe
%AppData%\microsoft\dtsc\t.exe
%AppData%\microsoft\office71\vhchk.exe
%AppData%\microsoft\windows\ernsjyi.exe
%AppData%\microsoft\windows\jjcmdrj.exe
%AppData%\microsoft\windows\nheste.exe
%AppData%\microsoft\windows\nxmwp.exe
%AppData%\microsoft\windows\rwmgh.exe
%AppData%\microsoft\windows\security\user0.exe
%AppData%\microsoft\windows\tbljxjk.exe
%AppData%\microsoft\windows\vohth.exe
%AppData%\microsoft\windows\vvpmyvaw.exe
%AppData%\mxplay\temp\mxplay_installer.exe
%AppData%\ntcom.dll
%AppData%\nthead.dll
%AppData%\pak-5593.exe
%AppData%\pak-5594.exe
%AppData%\pak-5595.exe
%AppData%\pak-5596.exe
%AppData%\pak-5597.exe
%AppData%\pak-5598.exe
%AppData%\pak-5599.exe
%AppData%\pak-5600.exe
%AppData%\pak-5601.exe
%AppData%\pak-5602.exe
%AppData%\pak-5603.exe
%AppData%\salehoo\auctionalert\_tmp\aa.exe
%AppData%\salehoo\salehooalert\_tmp\aa.exe
%AppData%\scvhost.exe
%AppData%\silverlight\silverlight.exe
%AppData%\skynet\muonline\_cw0srv.exe
%AppData%\skynet\muonline\234672.exe
%AppData%\skynet\muonline\239874.exe
%AppData%\skynet\muonline\293874.exe
%AppData%\skynet\muonline\345674.exe
%AppData%\skynet\muonline\345676.exe
%AppData%\skynet\muonline\435627.exe
%AppData%\skynet\muonline\543978.exe
%AppData%\skynet\muonline\546783.exe
%AppData%\speedrunner\sruninstall.exe
%AppData%\temp.dll
%AppData%\truesword4.exe
%AppData%\wefisetup.exe
%AppData%\winbutler\winbuninstaller.exe
%AppData%\winbutler\winbutler.exe
%AppData%\windows.exe
%AppData%\wintouch\wintouch.exe
%AppData%\wintouch\wtuninstaller.exe
%AppData%\wrar380d.exe
%AppData%\yeah\yeah374809.exe
%CommonAppData%\38001914.exe
%CommonAppData%\3810eef8.exe
%CommonAppData%\381751d0.exe
%CommonAppData%\388f0900.exe
%CommonAppData%\38d3ff69.exe
%CommonAppData%\aol downloads\aoltoolbar\setuptoolbar.exe
%CommonAppData%\av1\av1.exe
%CommonAppData%\av1\av1i.exe
%CommonAppData%\av1\av1i2.exe
%CommonAppData%\av1\av1two.exe
%CommonAppData%\av1\qwprotect.dll
%CommonAppData%\av1\svchost.exe
%CommonAppData%\av2010\av2010.exe
%CommonAppData%\av2010\iedefender.dll
%CommonAppData%\av2010\svchost.exe
%CommonAppData%\dyned\eng_loc.exe
%CommonAppData%\e4a12b7\extraav.exe
%CommonAppData%\e4a12b7\ua2009.exe
%CommonAppData%\e4a12b7\valarm.exe
%CommonAppData%\e4a12b7\vmelt.exe
%CommonAppData%\e4a12b7\vsweep.exe
%CommonAppData%\fetion\fetionupdate.exe
%CommonAppData%\gav\sgav.exe
%CommonAppData%\n1\n1.exe
%CommonAppData%\n1\n1i.exe
%CommonAppData%\n1\n1two.exe
%CommonAppData%\n1\qwprotect.dll
%CommonAppData%\n1\svchost.exe
%CommonAppData%\nexon\ngm\ngmdll.dll
%CommonAppData%\qw2010\qw2010.exe
%CommonAppData%\qw2010\qw2010i.exe
%CommonAppData%\qw2010\qw2010i2.exe
%CommonAppData%\qw2010\qwprotect.dll
%CommonAppData%\qw2010\svchost.exe
%CommonAppData%\storm\temp\update.exe
Notes:
  • %AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.

The file "7.exe" has the following possible countries of origin:
OriginNumber of Incidents
China4
Germany3
France2
Russian Federation2
United Kingdom2
Austria1
Israel1
Turkey1
Ukraine1

The following threats are known to be associated with the file "7.exe":
Threat AliasNumber of Incidents
Mal/EncPk-EU [Sophos]1,371
Trojan.Fakeavalert [Symantec]1,106
Trojan-Downloader.Exchanger.Gen.2 [Ikarus]993
Trojan.Fakeavalert!sd6 [PC Tools]865
BKDR_FRAUDER.PB [Trend Micro]861
Trojan:Win32/Tibs.ID [Microsoft]861
Generic.dx [McAfee]834
Backdoor.Win32.Frauder.fc [Kaspersky Lab]820
Backdoor.Frauder!sd6 [PC Tools]764
Trojan:Win32/Tibs.IH [Microsoft]545
Generic BackDoor [McAfee]369
Generic Downloader.x [McAfee]368
Backdoor.Win32.Frauder.lp [Kaspersky Lab]360
Trojan.Win32.Tibs [Ikarus]355
Mal/Generic-A [Sophos]337
Troj/FakeVir-GJ [Sophos]300
Packed.Generic.186 [Symantec]285
Trojan:Win32/Tibs.IF [Microsoft]284
Trojan.Zlob [Symantec]282
Tibs-Packed [McAfee]270
Backdoor.Win32.Frauder.fb [Kaspersky Lab]264
Backdoor.Win32.Frauder.kf [Kaspersky Lab]224
Troj/Bdoor-AOK [Sophos]224
Backdoor.Win32.Frauder.jt [Kaspersky Lab]212
Trojan Horse [Symantec]209
Trojan-Dropper.Agent [Ikarus]204
TrojanDownloader:Win32/Renos.AU [Microsoft]160
Trojan-Downloader.Win32.Hoaxer.a [Kaspersky Lab]149
Trojan-Downloader.Win32.Agent.aejp [Kaspersky Lab]145
Trojan-Downloader.Win32.Agent.aflr [Kaspersky Lab]143
Mal/EncPk-CZ [Sophos]114
Backdoor.Win32.Frauder.jt [Ikarus]113
Backdoor.Win32.Frauder.kf [Ikarus]96
Backdoor.Win32.Frauder.fb [Ikarus]82
TrojanDownloader:Win32/Renos.DU [Microsoft]82
Trojan-Downloader.Win32.Agent.aftn [Kaspersky Lab]81
Downloader.MisleadApp [Symantec]70
Trojan:Win32/Tibs.IG [Microsoft]63
Trojan-Downloader.Win32.Agent.aigp [Kaspersky Lab]63
RogueAntiSpyware.PCHealthCenter [PC Tools]50
Downloader.gen.a [McAfee]40
TROJ_AGENT.UIH [Trend Micro]40
Trojan-Downloader.Hoaxer!sd6 [PC Tools]40
Backdoor.Win32.Frauder [Ikarus]32
Downloader [Symantec]16
Mal/Packer [Sophos]15
Backdoor.Win32.Frauder.oc [Kaspersky Lab]10
Generic Downloader.z [McAfee]10
Trojan-Downloader.Win32.VB.avo [Ikarus]9
Trojan-Downloader.Win32.Agent.xkd [Kaspersky Lab]6
Generic Downloader.ab [McAfee]5
Virus.Win32.Small [Ikarus]5
Mal/VBDos-A [Sophos]4
Backdoor.Bifrose [Symantec]3
Backdoor.Bifrose!sd6 [PC Tools]3
Backdoor.Win32.Bifrose.abjs [Kaspersky Lab]3
BackDoor-CEP.gen.g [McAfee]3
Packed/FSG [PC Tools]3
Packed/Upack [AhnLab]3
Trojan.Generic [Ikarus]3
Win32.SuspectCrc [Ikarus]3
Win-Trojan/Downloader.3072.JG [AhnLab]3
Win-Trojan/Midgare.30208 [AhnLab]3
Win-Trojan/Xema.variant [AhnLab]3
Adware.Borlan [Symantec]2
Adware.Borlan!sd5 [PC Tools]2
Backdoor.Sdbot [Symantec]2
Backdoor.Trojan [Symantec]2
Backdoor.Win32.PoeBot.C [Ikarus]2
BKDR_AHZE.NY [Trend Micro]2
Cryp_PESpin [Trend Micro]2
Infostealer.Phax [Symantec]2
Infostealer.Refest [Symantec]2
Mal/EncPk-FH [Sophos]2
Mal/EncPk-HL [Sophos]2
New Malware.aj [McAfee]2
New Malware.d [McAfee]2
not-a-virus.Keygen.NfS [Ikarus]2
not-a-virus:PSWTool.Win32.MailPassView.a [Kaspersky Lab]2
PSWTool.MailPassView!sd5 [PC Tools]2
Suspicious.MH690 [Symantec]2
Trojan.Voxom [Symantec]2
Trojan.Voxom!sd6 [PC Tools]2
Trojan.Win32.Midgare [Ikarus]2
Trojan:Win32/Midgare.A [Microsoft]2
Trojan-Downloader.Win32.Small [Ikarus]2
Trojan-PSW.Refest [PC Tools]2
Trojan-PWS.OnlineGames.AHRG [PC Tools]2
Virus.Win32.Bifrose [Ikarus]2
Win32/IRCBot.worm.variant [AhnLab]2
AdWare.Agent [Ikarus]1
BKDR_AHZE.SMM [Trend Micro]1
BraveSentry [McAfee]1
Downloader.Trojan [Symantec]1
Generic Downloader.f [McAfee]1
Generic.dx!fh [McAfee]1
HackTool.Win32.Kiser [Ikarus]1
HackTool.Win32.Kiser.bh [Kaspersky Lab]1
Mal/Behav-328, Mal/Behav-009 [Sophos]1
Mal/Bifrose-X, Mal/EncPk-FH [Sophos]1