File Behavior
CBBLEEPINGREGISTRYBOOSTER[n].EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- Executes Processes stored in Temporary Folders
- Creates system tray popups, messages, errors and security warnings
CBBLEEPINGREGISTRYBOOSTER[n].EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename CBBLEEPINGREGISTRYBOOSTER[n].EXE was first seen on Oct 5 2008 in the following geographical regions of the Prevx community:
- EGYPT on Oct 5 2008
- INDIA on Oct 8 2008
- The EUROPEAN UNION on Jun 26 2009
File Name Aliases
CBBLEEPINGREGISTRYBOOSTER[n].EXE can also use the following file names:
- CA.EXE
- CBBLEEPINGREGISTRYBOOSTER.EXE
- Рабочий стол
Filesizes
The following file size has been seen:
- 1,676,152 bytes
- 936,851 bytes
- 1,758,384 bytes
File Type
The filename CBBLEEPINGREGISTRYBOOSTER[n].EXE refers to many versions of an executable program.
File Activity
One or more files with the name CBBLEEPINGREGISTRYBOOSTER[n].EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\docume~1\user\locals~1\temp\mia8.tm
- Creates c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.msi
- Creates c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.exe
- Creates c:\docume~1\user\locals~1\temp\mia8.tmp\mia.lib
- Creates c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.res
- Deletes c:\docume~1\user\locals~1\temp\mia8.tmp\mia.lib
- Deletes c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.exe
- Deletes c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.msi
- Deletes c:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.res
- Creates c:\docume~1\user\locals~1\temp\lang.loc
- Deletes c:\docume~1\user\locals~1\temp\lang.loc
- Creates c:\docume~1\user\locals~1\temp\mia.tmp
- Deletes c:\docume~1\user\locals~1\temp\mia.tmp
- Creates c:\docume~1\user\locals~1\temp\mia1\anim.gif
- Creates c:\docume~1\user\locals~1\temp\mia1\componentstree.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\destination.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\finish.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\icon.ico
- Creates c:\docume~1\user\locals~1\temp\mia1\index.htm
- Creates c:\docume~1\user\locals~1\temp\mia1\license.rtf
- Creates c:\docume~1\user\locals~1\temp\mia1\licensecheck.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\maintenance.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\prereq.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\progress.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\progressprereq.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\readme.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\registration.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\registrationwithserial.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\setuptype.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\startinstallation.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\startmenu.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\welcome.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\wizard.dfm
- Creates c:\docume~1\user\locals~1\temp\mia1\InstallerExtensions.dll
- Creates c:\docume~1\user\locals~1\temp\mia1\mEXEFunc.dll
- Creates c:\docume~1\user\locals~1\temp\mia1\mMSIExec.dll
- Creates c:\docume~1\user\locals~1\temp\mia1\mWinRunExec.dll
- Copies filec:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.msi to c:\docume~1\user\locals~1\temp\mia1\Uniblue RegistryBooster.msi
- Copies filec:\docume~1\user\locals~1\temp\mia8.tmp\Uniblue RegistryBooster.msp to c:\docume~1\user\locals~1\temp\mia1\Uniblue RegistryBooster.msp
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.