Associated Malware Groups
The filename is associated with the malware group:
File Behavior
WINNICMKI.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Adds products to the system registry
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Writes to another Process's Virtual Memory (Process Hijacking)
- Creates a TCP port which listens and is available for communication initiated by other computers
- This Process Deletes Other Processes From Disk
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- This process creates other processes on disk
- Terminates Processes
- Sends email using SMTP protocols
WINNICMKI.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename WINNICMKI.EXE was first seen on Dec 6 2009 in the following geographical regions of the Prevx community:
- Georgia on Dec 6 2009
- The United Kingdom on Dec 6 2009
Filesizes
This file has been seen with the following file size:
File Type
The filename WINNICMKI.EXE refers to an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.