Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Rootkit
- Malware Dropper
- Malicious Software
File Behavior
16.TMP has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Copies files
- Checks for the use of debuggers
- Looks at the contents of the autoexec.bat file
- Uses physical device level disk access which could bypass security applications and checks
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
- Registers a Dynamic Link Library File
16.TMP has been the subject of the following behavior:
- Created as a process on disk
- Registered as a Dynamic Link Library File
- Executed as a Process
Country Of Origin
The filename 16.TMP was first seen on Sep 9 2009 in the following geographical regions of the Webroot community:
- Europe on Sep 9 2009
- Ukraine on Sep 16 2009
- France on Oct 21 2010
- Algeria on Oct 21 2010
- South Africa on Nov 22 2010
- Australia on Nov 22 2010
- Mexico on May 22 2012
File Name Aliases
16.TMP can also use the following file names:
- QLUTE.EXE
- SOFT4[1].EXE
- TFTP.NFO
- 3D.TMP
- 46.TMP
- 11.TMP
- EA.TMP
- 3E.TMP
- 19.TMP
- D5.TMP
- 7A6F.TMP
- 1445.TMP
Filesizes
The following file size has been seen:
- 25,600 bytes
- 355,840 bytes
- 180,736 bytes
- 54,784 bytes
- 139,776 bytes
- 55,808 bytes
File Type
The filename 16.TMP is used by multiple object types including Dynamic Link LIbraries,executable programs.
File Activity
One or more files with the name 16.TMP creates, deletes, copies or moves the following files and folders:
- Opens/modifes c:\autoexec.bat
- Copies filec:\windows\system32\drivers\beep.sys to c:\docume~1\user\locals~1\temp\6.tmp
- Creates c:\windows\system32\drivers\beep.sys
- Copies filec:\docume~1\user\locals~1\temp\6.tmp to c:\windows\system32\drivers\beep.sys
- Deletes c:\docume~1\user\locals~1\temp\6.tmp
- Copies filec:\windows\system32\drivers\null.sys to c:\docume~1\user\locals~1\temp\B.tmp
- Creates c:\windows\system32\drivers\null.sys
- Copies filec:\docume~1\user\locals~1\temp\B.tmp to c:\windows\system32\drivers\null.sys
- Deletes c:\docume~1\user\locals~1\temp\B.tmp
- Creates c:\windows\system32\drivers\glaide32.sys
Website Activity
One or more files with the name 16.TMP interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- 174 .139 .241
- Port 80 IP:174.139.241.2
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.