File Behavior
AIMSNIFFER_TRIAL_SETUP[1].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- This process creates other processes on disk
- This Process Deletes Other Processes From Disk
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Creates system tray popups, messages, errors and security warnings
AIMSNIFFER_TRIAL_SETUP[1].EXE has been the subject of the following behavior:
- Deleted as a process from disk
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
Country Of Origin
The filename AIMSNIFFER_TRIAL_SETUP[1].EXE was first seen on Feb 14 2008 in the following geographical regions of the Prevx community:
- France on Feb 14 2008
- The United States on Feb 14 2008
File Name Aliases
AIMSNIFFER_TRIAL_SETUP[1].EXE can also use the following file names:
- AIMSNIFFER_TRIAL_SETUP[n].EXE
- AIMSNIFFER_TRIAL_SETUP.EXE
- AIMSNIFFER_TRIAL_SETUP (n).EXE
Filesizes
This file has been seen with the following file size:
File Type
The filename AIMSNIFFER_TRIAL_SETUP[1].EXE refers to an executable program.
File Activity
One or more files with the name AIMSNIFFER_TRIAL_SETUP[1].EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\GLKD.tmp
- Deletes c:\docume~1\user\locals~1\temp\GLB10.tmp
- Creates c:\docume~1\user\locals~1\temp\GLG12.tmp
- Creates c:\docume~1\user\locals~1\temp\~GLH0000.TMP
- Deletes c:\docume~1\user\locals~1\temp\GLF14.tmp
- Moves c:\docume~1\user\locals~1\temp\~GLH0000.TMP to c:\docume~1\user\locals~1\temp\GLF14.tmp
- Creates c:\docume~1\user\locals~1\temp\~GLH0001.TMP
- Deletes c:\docume~1\user\locals~1\temp\GLF17.tmp
- Moves c:\docume~1\user\locals~1\temp\~GLH0001.TMP to c:\docume~1\user\locals~1\temp\GLF17.tmp
- Creates c:\docume~1\user\locals~1\temp\~GLH0002.TMP
- Deletes c:\docume~1\user\locals~1\temp\GLF19.tmp
- Moves c:\docume~1\user\locals~1\temp\~GLH0002.TMP to c:\docume~1\user\locals~1\temp\GLF19.tmp
- Creates c:\windows\system32\GLBSINST.%$D
- Deletes c:\windows\system32\GLBSINST.%$D
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.