SSVICHOSST.EXE - Dangerous

What you should do about SSVICHOSST.EXE:

You should urgently check your PC and remove any malicious software including SSVICHOSST.EXE as soon as possible.

The free version of Prevx CSI will scan your PC for millions of spyware and malware infections in less than 2 minutes. Don't take the risk, check your PC now.

Download Prevx CSI Now

What we know about SSVICHOSST.EXE:

SSVICHOSST.EXE

AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:

DEFINITION OF: SSVICHOSST.EXE

  • Safety Rating: Known malware, do not run
  • Determination: Automatically determined using Prevx centralized heuristics
  • Protection: Prevx provides powerful security products that you can use to detect, remove and protect you from SSVICHOSST.EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
  • Why risk having spyware on your PC when it takes less than 2 minutes to thoroughly check it with Prevx CSI? Click here to check your PC with Prevx CSI Now.
  • First seen: Mar 14 2007 (GMT)
  • Last seen: Mar 14 2007 (GMT)
  • File Size: 239,905 bytes
MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY

1. COVERT ANALYSIS OF: SSVICHOSST.EXE

  • File Names Used: 365
  • Paths Used: 357
  • Common File Name: SSVICHOSST.EXE
  • Common Path: %WINDIR%\SYSTEM32\
  • Vendor Information: No Vendor details specified
  • SSVICHOSST.EXE may use 365 or more path and file names, these are the most common:
  • 1 :%desktop%\very useful\mca...2008 (retail)-heartbug\MCAFEE TOTAL PROTECTION 2008.....EXE
  • 2 :%documents%\clã©\CLé.EXE
  • 3 :%DOCUMENTS%\DOWNLOADS\PROGRAMS\HINHEM.EXE
  • 4 :%DOCUMENTS%\NEW FOLDER.EXE
  • 5 :%STARTMENU%\DéMARRAGE.EXE
  • 6 :?:\adobe acrobat professional 8.10\ADOBE ACROBAT PROFESSIONAL 8.....EXE
  • 7 :?:\alamin-d\dcs\NEW FOLDER.EXE
  • 8 :?:\مجلد 22\مجلد 22.EXE
  • 9 :?:\مجلد جديد (2)\مجلد جدÙÂ.....EXE
  • 10:?:\clefusb\cps par lot\CPS PAR LOT.EXE
  • 11:?:\clefusb\dossiers en in...ce\article.md_fichiers\ARTICLE.MD_FICHIERS.EXE
  • 12:?:\easyphp\www\yacs\agents\user-agents\USER-AGENTS.EXE
  • 13:?:\epu\josir\JOSIR.EXE
  • 14:?:\helal\HELAL.EXE
  • 15:?:\index\INDEX.EXE
  • File Name Structure: Normal
  • File and Path Structure: Suspicious, unusually high number of file and path combinations

2. RELATIONSHIP ANALYSIS OF: SSVICHOSST.EXE

  • Malicious Objects Created: 2 objects
  • Malicious Creators: 2
  • Malware Run Keys: None
  • Self Persists:
  • Antivirus Detection: No third party antivirus detection observed
  • Anti-Spyware Detection: No third party anti-spyware detection observed

3. ACTIVITY ANALYSIS OF: SSVICHOSST.EXE

  • The following behaviors have been observed for this object:
  • Installs programs.
  • Deletes programs.
  • Invokes dll components.
  • Creates Run Keys.
  • Runs other programs.
  • Communicates with web sites using httpout protocols.
  • Terminates processes.
  • Has outbound communications.
  • Creates known malware.
  • Creates copies of itself.

4. PROPAGATION ANALYSIS OF: SSVICHOSST.EXE

  • Object Propagation Rate: Very Low (minimal spread)
  • Copyright Prevx Limited 2005, 2006
  Other versions of SSVICHOSST.EXE

Copyright Prevx Ltd
Page Generated on Nov 22, 2008 2:35