Associated Malware Groups
The filename is associated with the malware group:
File Behavior
WINBEGHVT.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Disables the built in Windows File Protection System
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- This process creates other processes on disk
- Executes a Process
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Writes to another Process's Virtual Memory (Process Hijacking)
- Can communicate with other computer systems using HTTP protocols
- This Process Deletes Other Processes From Disk
- Adds a Registry Key (RUN) to auto start Programs on system start up
WINBEGHVT.EXE has been the subject of the following behavior:
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Executed as a Process
Country Of Origin
The filename WINBEGHVT.EXE was first seen on Jul 25 2008 in the following geographical region of the Prevx community:
- The UNITED KINGDOM on Jul 25 2008
Filesizes
The following file size has been seen:
- 35,840 bytes
- 42,492 bytes
File Type
The filename WINBEGHVT.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.