Associated Malware Groups
The filename is associated with the malware group:
File Behavior
KVMVU.EXE has been seen to perform the following behavior:
- Executes a Process
- Injects code into other processes
- Copies files
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Modifies Windows Initialization And System Settings Used On Start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds a Registry Key (RUN) to auto start Programs on system start up
- The Process is packed and/or encrypted using a software packing process
KVMVU.EXE has been the subject of the following behavior:
- Executed as a Process
- Copied to multiple locations on the system
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
Country Of Origin
The filename KVMVU.EXE was first seen on Nov 3 2009 in the following geographical regions of the Prevx community:
- The EUROPEAN UNION on Nov 3 2009
- SINGAPORE on Nov 5 2009
- NEW CALEDONIA on Nov 5 2009
- ISRAEL on Nov 7 2009
- ARGENTINA on Nov 14 2009
- TURKEY on Nov 14 2009
- INDONESIA on Nov 16 2009
File Name Aliases
KVMVU.EXE can also use the following file names:
- MATDTB.EXE
- CQJUGF.EXE
- PENMRDYA.EXE
- PAFNTPNA.EXE
- SKYPE.EXE
- ILMVM.EXE
- EWMQLTDF.EXE
- DPLYRS~1.EXE
- LUPRTH.EXE
- EOPSL.EXE
- YEADTKO.EXE
- BPRMYES.EXE
- GCXU.EXE
- HLTT.EXE
- ZBUREOLIRO[1].HTM
- EEAKCOW.EXE
- TNTMKQV.EXE
- UJGYJDNB.EXE
- QWTDNNKU[1].HTM
- DATA.TMP
- MWYLVE.EXE
- RNMSMBS.EXE
- FNHEI.EXE
- MSSRV32.EXE
- H586X.EXE
Filesizes
The following file size has been seen:
- 40,448 bytes
- 94,208 bytes
- 110,080 bytes
- 40,960 bytes
- 131,072 bytes
- 138,240 bytes
- 208,384 bytes
File Type
The filename KVMVU.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.