Associated Malware Groups
The filename is associated with the malware groups:
- Fraudulent Security Program
- Cloaked Malware
- Malicious Software
File Behavior
NCVYSO.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Found on infected systems and resists interrogation by security products
- Writes to another Process's Virtual Memory (Process Hijacking)
- Can communicate with other computer systems using HTTP protocols
- Executes Processes stored in Temporary Folders
- This process creates other processes on disk
- Executes a Process
- Registers a Dynamic Link Library File
- Creates or uses a background service to access the Internet using HTTP protocols
- Injects code into other processes
- This Process Deletes Other Processes From Disk
- Modifies Windows Initialization And System Settings Used On Start up
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Creates, registers ot modifies and SMTP Server
- Creation and Registration of a Browser Helper Object in Internet Explorer
- Enables an In Process Object/Server - Common with DLL Injections
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Installs a browser helper object (BHO)
NCVYSO.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Terminated as a Process
- Registered as a Dynamic Link Library File
Country Of Origin
The filename NCVYSO.EXE was first seen on Nov 3 2009 in the following geographical regions of the Prevx community:
- The UNITED STATES on Nov 3 2009
- GERMANY on Nov 4 2009
- COLOMBIA on Nov 5 2009
- BRAZIL on Nov 9 2009
- GREAT BRITAIN on Nov 9 2009
- CANADA on Nov 11 2009
File Name Aliases
NCVYSO.EXE can also use the following file names:
- NOBH[1].EXE
- EINNTRTFG.EXE
- MGSXNHDN.EXE
- TDLKR.EXE
- GNLDA.EXE
- QUTEYD.EXE
- MVAT.EXE
- EMAHBIP.EXE
- ZXFLPXW.EXE
- KSMDWNK.EXE
- KLTJQBY.EXE
- YLTJO.EXE
- XSYVVSF[1].HTM
- MCUJC.EXE
- XFVPYV.EXE
- LUOBK.EXE
- VMPBWE.EXE
- CVESFWK[1].HTM
- QOYE.EXE
- LOAD.EXE
- 8.TMP
- DC147.EXE
- 32834604.DAT
Filesizes
The following file size has been seen:
- 47,104 bytes
- 91,136 bytes
- 52,736 bytes
- 75,264 bytes
- 51,200 bytes
- 36,925 bytes
File Type
The filename NCVYSO.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.