File Behavior
SUPERVV.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Creates a new Background Service on the machine
- This process creates other processes on disk
- Loads and Executes a System Driver File
- This Process Deletes Other Processes From Disk
- Ability to execute files automatically on your PC
- Can communicate with other computer systems using HTTP protocols
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- Executes a Process
- Registers a Dynamic Link Library File
- Disables safe mode on your PC
- Checks for the use of debuggers
- Found on infected systems and resists interrogation by security products
- Changes to the file command map within the registry
- Enables a COM Object/Server on the Local Machine
- Copies files
- Injects code into other processes
- Creates new folders on the system
SUPERVV.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Deleted as a process from disk
- Copied to multiple locations on the system
- Registered as a Dynamic Link Library File
Country Of Origin
The filename SUPERVV.EXE was first seen on Nov 9 2009 in the following geographical regions of the Prevx community:
- CHINA on Nov 9 2009
- GREAT BRITAIN on Nov 9 2009
File Name Aliases
SUPERVV.EXE can also use the following file names:
- WUAUOLTS.EXE
- MOSSS.EXE
- QGS.EXE
- EXPLORER.EXE
- BWC.EXE
Filesizes
The following file size has been seen:
- 172,050 bytes
- 177,682 bytes
File Type
The filename SUPERVV.EXE refers to many versions of an executable program.
Website Activity
One or more files with the name SUPERVV.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:127.0.0.1:1104 Port:22
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.