SCVVHSOT.EXE - Dangerous

What you should do about SCVVHSOT.EXE:

Your PC is infected. The file called SCVVHSOT.EXE is considered unsafe and there may be other infections on your PC.

You should urgently check your PC and remove any malicious software including SCVVHSOT.EXE as soon as possible. The free version of Prevx CSI will scan your PC for millions of spyware and malware infections in less than 2 minutes. Don't take the risk, check your PC now.

Download Prevx CSI Now

What we know about SCVVHSOT.EXE:

The filename SCVVHSOT.EXE was first seen on Jul 5 2007 in The UNITED KINGDOM. It has also been seen in the following geographical regions of the Prevx community:

  • SPAIN on Sep 15 2007
  • UGANDA on Jul 2 2008
  • PAKISTAN on Aug 27 2007
  • PHILIPPINES on Oct 8 2007
The filename SCVVHSOT.EXE refers to many versions of an executable program.

The most common file size is 290,816 bytes. But the following file sizes have also been seen:

  • 290,419 bytes
  • 331,776 bytes
  • 506,995 bytes
  • 300,544 bytes
  • 468,448 bytes

The filename is associated with the malware group Worm/Autoit.ER.Some files using the name SCVVHSOT.EXE are also associated with the malware groups:

  • Worm/Autoit.PV
  • WORM.IM.SOHANAD.L
These files have no vendor, product or version information specified in the file header.

SCVVHSOT.EXE has been seen to perform the following behavior(s):

  • The Process is packed and/or encrypted using a software packing process
  • Disables the built in Windows File Protection System
  • Modifies Windows Security Policies to restrict/expand User Privileges on the machine
  • Disables Access to the Task Manager built into Windows
  • Disables Access to the Windows Registry Editior
  • Adds a Registry Key (RUN) to auto start Programs on system start up
  • This Process Creates Other Processes On Disk
  • This Process Deletes Other Processes From Disk
  • Executes a Process
  • Creates a new Background Service on the machine
  • Looks at the contents of the autoexec.bat file
  • Reads email address and phone book details
  • Visits web sites on your PC without you knowing
  • Can communicate with other computer systems using HTTP protocols
  • Makes outbound connections to other computers using NETBIOSOUT protocols
  • Enables the system to use a Communications Proxy Server
  • Registers a Dynamic Link Library File
  • The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents

SCVVHSOT.EXE has been the subject of the following behavior(s):

  • Added as a Registry auto start to load Program on Boot up
  • Created as a process on disk
  • Executed as a Process
  • Terminated as a Process
  • Copied to multiple locations on the system
  • Created by processes which appear to be checking for interception by security products
  • Deleted as a process from disk
  • Has code inserted into its Virtual Memory space by other programs

SCVVHSOT.EXE can also use the following file names:

  • 90'S.EXE
  • NEW FOLDER.EXE
  • BLASTCLNNN.EXE
  • DPTRIPPBHB-370.PMS.EXE
  • B7BF1EAECE93FDDC862217C9281595F2.EXE
  • 57393276.SVD
  • WINDOWS.EXE
  • 96219206.EXE
  • VS1C4F30.~VSTMP~~
  • VS2A9D4C.~VSTMP~~
  • VS2F6200.~VSTMP~~
  • VS532546.~VSTMP~~
  • DPE.EXE
  • AUGUST 2007 2ND WEEK.EXE
  • EA GAMES.EXE
  • 16782981.SVD
  • 94691636.EXE
  • DD2.EXE
  • DOC STAMPS COMPUTATION.EXE
  • XSCVVHSOT.EXE
  • DPTRMWWDBG-767.PMS.EXE
  • 569DC402531CCCF02A24E9D98A7772D3.EXE
  • DOWNLOADS.EXE
  • DH106.EXE
  • CCB.EXE
  • DH107.EXE
  • RHLI.EXE
  • COST PER AREA.EXE
  • DH22.EXE
  • UNIT COST BY ELEMENT.EXE
  • DH23.EXE
  • UNIT COST BY TRADE.EXE
  • DH24.EXE
  • UNIT COST TOTAL.EXE
  • PUNTA.EXE