Associated Malware Groups
The filename is associated with the malware group:
- Fraudulent Security Program
File Behavior
LDVLHBEE.EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds a Registry Key (RUNONCE) to auto start Programs on system start up
- Executes Processes stored in Temporary Folders
- This process creates other processes on disk
- Executes a Process
- Creates new folders on the system
- This Process Deletes Other Processes From Disk
- Creates a new Background Service on the machine
- The Process is packed and/or encrypted using a software packing process
- Modifies Windows Initialization And System Settings Used On Start up
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Registers a Dynamic Link Library File
- Injects code into other processes
- Creates, registers ot modifies and SMTP Server
LDVLHBEE.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename LDVLHBEE.EXE was first seen on Nov 20 2009 in the following geographical regions of the Prevx community:
- The United States on Nov 20 2009
- India on Nov 20 2009
- The United Kingdom on Nov 23 2009
File Name Aliases
LDVLHBEE.EXE can also use the following file names:
- NEQPNLH.EXE
- JYFBCC[1].HTM
- EXARFSG.EXE
- XRVHO.EXE
- PJQELX.EXE
- HRUVL.EXE
- EXHSTDB.EXE
- $RTEP7V1.EXE
- 26155139.EXE
Filesizes
The following file size has been seen:
- 147,968 bytes
- 75,264 bytes
- 52,736 bytes
File Type
The filename LDVLHBEE.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.