Associated Malware Groups
The filename is associated with the malware group:
File Behavior
AMVO.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This Process Deletes Other Processes From Disk
- Loads and Executes a System Driver File
- This process creates other processes on disk
- The Process is polymorphic and can change its structure
- Executes a Process
- Injects code into other processes
- Writes to another Process's Virtual Memory (Process Hijacking)
- Registers a Dynamic Link Library File
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Can communicate with other computer systems using HTTP protocols
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Copies files
- Disables safe mode on your PC
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- This Process looks to see what security products and services are running on the system
- Creates a new Background Service on the machine
- Looks at the contents of the autoexec.bat file
- Drops known malicious software during execution
- Accesses web sites that have been associated with malicious software
- Reads email address and phone book details
- Uses backdoor interfaces to certain security applications
- Disables or impairs the normal operation of the Windows Security Center
- Uses DNS to retrieve the IP address for web sites
- Visits web sites on your PC without you knowing
- Violates Prevx File Security Settings
- Modifies Windows Initialization And System Settings Used On Start up
- Terminates Processes
AMVO.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Executed from Temporary Folders
- Downloaded from covert web sites without the user knowing
- Copied to multiple locations on the system
- This program is often downloaded from the web
- Registered as a Dynamic Link Library File
- Executed by Internet Explorer
- Terminated as a Process
- Created as a new Background Service on the machine
- Has code inserted into its Virtual Memory space by other programs
- This Process may have been infected by a file infecting virus
Country Of Origin
The filename AMVO.EXE was first seen on Dec 8 2007 in the following geographical regions of the Webroot community:
- Peru on Dec 8 2007
- South Africa on Dec 21 2007
- Spain on Aug 14 2009
- Russian Federation on Apr 10 2010
- The United Kingdom on Apr 10 2010
File Name Aliases
AMVO.EXE can also use the following file names:
- CFDFLX.COM
- W32ONLINEGAMES!I115.EXE
- XPBKH.COM
- A638BB~1.COM
- RTHRW.COM
- RTHRW.COM.BAK
- XYW9TMDJ.COM
- JIWSXH39.EXE
- W32ONLINEGAMES!I242.EXE
- XLU8A8SY.EXE
- NIDEIECT.COM
- HELP[1].EXE
- HELP[2].EXE
- MGG[1].EXE
- UXDEIECT.COM
- AMVO(n).EXE
- SAMPLE.COM
- UXDEIECT(n).COM
- HELP.EXE
- HELP[n].EXE
- HELP.EXE.TMP
- MGG.EXE
- MGG[n].EXE
- V.CMD
- Q.COM
Filesizes
The following file size has been seen:
- 100,791 bytes
- 135,168 bytes
- 103,624 bytes
- 124,928 bytes
- 201,728 bytes
- 123,422 bytes
- 121,918 bytes
File Type
The filename AMVO.EXE refers to many versions of an executable program.
File Activity
One or more files with the name AMVO.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\windows\system32\wmdrtc32.dl_
- Deletes c:\windows\system32\drivers\gnijqn.sys
- Creates c:\windows\system32\drivers\gnijqn.sys
- Creates c:\KUKU400alpha
- Creates d:\KUKU400alpha
- Deletes c:\KUKU400alpha
- Creates f:\KUKU400alpha
- Creates g:\KUKU400alpha
- Creates h:\KUKU400alpha
- Creates i:\KUKU400alpha
- Deletes d:\KUKU400alpha
- Creates j:\KUKU400alpha
- Creates k:\KUKU400alpha
- Creates l:\KUKU400alpha
- Creates m:\KUKU400alpha
- Creates n:\KUKU400alpha
- Creates o:\KUKU400alpha
- Creates p:\KUKU400alpha
- Creates q:\KUKU400alpha
- Creates y:\KUKU400alph
- Creates z:\KUKU400alph
- Opens/modifes c:\autoexec.bat
- Creates c:\docume~1\user\locals~1\temp\e13e_appcompat.txt
- Deletes c:\windows\system32\drivers\grrjf.sy
- Creates c:\windows\system32\drivers\grrjf.sys
- Creates c:\docume~1\user\locals~1\temp\winmesj.exe
- Deletes c:\docume~1\user\locals~1\temp\winmesj.ex
- Creates c:\docume~1\user\locals~1\temp\winxtfaol.exe
- Deletes c:\docume~1\user\locals~1\temp\winxtfaol.ex
- Creates c:\docume~1\user\locals~1\temp\idpfu.exe
- Deletes c:\docume~1\user\locals~1\temp\idpfu.ex
- Creates c:\docume~1\user\locals~1\temp\winohox.exe
- Deletes c:\docume~1\user\locals~1\temp\winohox.exe
- Creates c:\docume~1\user\locals~1\temp\winotgpw.exe
- Deletes c:\docume~1\user\locals~1\temp\winotgpw.ex
- Creates c:\docume~1\user\locals~1\temp\wjimoj.exe
- Deletes c:\docume~1\user\locals~1\temp\wjimoj.exe
- Creates c:\docume~1\user\locals~1\temp\winqhrl.exe
- Deletes c:\docume~1\user\locals~1\temp\winqhrl.exe
- Creates c:\docume~1\user\locals~1\temp\winreihxo.exe
- Deletes c:\docume~1\user\locals~1\temp\winreihxo.exe
- Creates c:\docume~1\user\locals~1\temp\ruhrsx.exe
- Deletes c:\docume~1\user\locals~1\temp\ruhrsx.ex
- Creates c:\docume~1\user\locals~1\temp\kdwwu.exe
- Deletes c:\docume~1\user\locals~1\temp\kdwwu.ex
- Creates c:\docume~1\user\locals~1\temp\bbcved.exe
- Deletes c:\docume~1\user\locals~1\temp\bbcved.ex
- Creates c:\docume~1\user\locals~1\temp\bvdwem.exe
- Deletes c:\docume~1\user\locals~1\temp\bvdwem.exe
- Creates c:\docume~1\user\locals~1\temp\winelyw.exe
Network Activity
One or more files with the name AMVO.EXE performs the following network events:
- DNS Lookup207.46.19.190 www.microsoft.com
- DNS Lookup64.12.222.197 mailin-01.mx.aol.com
- DNS Lookup68.142.202.247 d.mx.mail.yahoo.com
Website Activity
One or more files with the name AMVO.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- www .kukutrustnet666 .info / mrow_nrl / ?rnd=124250&id=1237501576
- mattfoll .eu .interia .
- st1 .dist .su .
- lpbmx .
- bjerm .mass .hc .
- SOSiTE_AVERI_SOSiTEEE .hahah?22c27=113900
- SOSiTE_AVERI_SOSiTEEE .hahah?24ea3=120962
- SOSiTE_AVERI_SOSiTEEE .hahah?2674b=78757
- SOSiTE_AVERI_SOSiTEEE .hahah?27bae=130187
- Port 80 IP:217.74.65.163
- Port 80 IP:89.149.227.194
- Port 80 IP:72.232.11.26
- Port 80 IP:193.219.168.18
- Port 80 IP:88.212.197.62
- Port 80 IP:89.111.173.114
- hgfdujt .info / ?21d1
- hgfdujt .info / i .ph
- hgfdujt .info / myh .ph
- 195 .24 .77 .223 / utest / ?jutr=17941&oo=2&2430a=fd546&ra=
- 195 .24 .77 .223 / utest / ?jutr=17941&oo=2&25ea0=109660&ra=
- hgfdujt .info / ?2642
- TCP:64.12.222.197:25 Port:14
- Port 80 IP:195.24.77.223
- TCP:64.12.222.197:25 Port:18
- TCP:68.142.202.247:25 Port:18
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.