Associated Malware Groups
The filename is associated with the malware groups:
- System Back Door
- Cloaked Malware
- Worm
File Behavior
RVHOST.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Copies files
- Executes a Process
- Injects code into other processes
- This Process looks to see what security products and services are running on the system
- Sets processes to start during user logon
- Disables safe mode on your PC
- Creates a new Background Service on the machine
- Drops known malicious software during execution
- Disables or impairs the normal operation of the Windows Security Center
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Disables Access to the Windows Registry Editior
- Disables Access to the Task Manager built into Windows
- Disables the built in Windows File Protection System
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Writes to another Process's Virtual Memory (Process Hijacking)
- Registers a Dynamic Link Library File
- Can communicate with other computer systems using HTTP protocols
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
- Creates, modifies or schedules batch jobs
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Hooks the WININET.DLL function allowing it to read or copy Http and Https web page content and session information
- Injects code into other processes
- Performs DNS look ups to resolve URL IP addresses
- Creates or uses a background service to access the Internet using HTTP protocols
RVHOST.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Copied to multiple locations on the system
- Executed as a Process
- Created as a new Background Service on the machine
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Terminated as a Process
- Deleted as a process from disk
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename RVHOST.EXE was first seen on May 8 2007 in the following geographical regions of the Webroot community:
- on May 8 2007
- Saudi Arabia on May 8 2007
- Vietnam on May 22 2007
- Malaysia on Jun 5 2007
- Hong Kong on Aug 31 2008
- Spain on Aug 23 2009
- Turkey on Jan 9 2010
- The United Kingdom on Jan 9 2010
Filesizes
The following file size has been seen:
- 489,472 bytes
- 337,947 bytes
- 702,418 bytes
- 268,216 bytes
- 268,288 bytes
- 506,995 bytes
- 659,896 bytes
- 428,032 bytes
File Type
The filename RVHOST.EXE is used by multiple object types including objects,executable programs,objects.
File Activity
One or more files with the name RVHOST.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\system32\drivers\hlmfln.sy
- Creates c:\windows\system32\drivers\hlmfln.sys
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.