Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
WMIPRVES[1].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This Process Deletes Other Processes From Disk
- Executes a Process
- Registers a Dynamic Link Library File
- Can communicate with other computer systems using HTTP protocols
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- This process creates other processes on disk
- Terminates Processes
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Creates a new Background Service on the machine
WMIPRVES[1].EXE has been the subject of the following behavior:
- Created as a process on disk
- Deleted as a process from disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Created as a new Background Service on the machine
Country Of Origin
The filename WMIPRVES[1].EXE was first seen on Aug 21 2007 in the following geographical regions of the Prevx community:
- The UNITED ARAB EMIRATES on Aug 21 2007
- PHILIPPINES on Aug 30 2007
- The EUROPEAN UNION on Nov 19 2007
- SPAIN on May 5 2008
File Name Aliases
WMIPRVES[1].EXE can also use the following file names:
- WMIPRVES[3].EXE
- NTDNS.SYS
- NDT.SYS
- NDT2.SYS
- WMIPRVES.EXE
- WMIPRVES[2].EXE
- \\
Filesizes
The following file size has been seen:
- 279,040 bytes
- 32,212 bytes
- 84,276 bytes
- 978,944 bytes
- 257,024 bytes
- 321,932 bytes
File Type
The filename WMIPRVES[1].EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.