Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
OVER.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Enables an In Process Object/Server - Common with DLL Injections
- Adds a Registry Key (RUN) to auto start Programs on system start up
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Adds products to the system registry
- Registers a Dynamic Link Library File
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
OVER.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Created as a new Background Service on the machine
Country Of Origin
The filename OVER.EXE was first seen on Jul 1 2007 in the following geographical regions of the Prevx community:
- Europe on Jul 1 2007
- Algeria on Jul 1 2007
File Name Aliases
OVER.EXE can also use the following file names:
- OVER_2.EXE
- OVERZ.EXE
- R1.EXE
- 82407603.DAT
- 98610684.EXE
Filesizes
The following file size has been seen:
- 392,704 bytes
- 2,236,416 bytes
- 3,584 bytes
- 17,999 bytes
File Type
The filename OVER.EXE is used by multiple object types including executable programs,objects.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.