Mal/EncPk-AFO

Category: Viruses and Spyware Protection available since:30 Jul 2012 11:59:19 (GMT)
Type: Malicious behavior Last Updated:15 Sep 2012 04:12:51 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/EncPk-AFO include:

Example 1

File Information

Size
234K
SHA-1
213a9262f9e0fc686a32a23d87f164228eff8de0
MD5
101d3eab42b06b5618b45de11f3ccbc6
CRC-32
ffc0f76d
File type
Windows executable
First seen
2012-04-30

Example 2

File Information

Size
98K
SHA-1
26f297b2b9377ab3ccd7fbdd16569de6d4a39ed1
MD5
90304b07ea9b8a02859ed4793a194c23
CRC-32
bcb3415a
File type
Windows executable
First seen
2012-06-17

Example 3

File Information

Size
117K
SHA-1
40cbecd9e0dbef19394e03749ff0691dee921178
MD5
144c085d70568dd323c25786ccee92fa
CRC-32
1104ee5e
File type
Windows executable
First seen
2011-01-27

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\4.tmp
Dropped Files
  • C:\WINDOWS\Temp\6.tmp
    Size
    117K
    SHA-1
    7f73a581c1cea062c0d03c57c14d0ec2f47bf26a
    MD5
    317248e89ffb5990b8ff14a6ffcc3e89
    CRC-32
    0b4be443
    File type
    Windows executable
    First seen
    2011-01-27
Registry Keys Created
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\international
    acceptlanguage
    en-gb
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    enablehttp1_1
    0x00000001
  • HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    maxhttpredirects
    0x000022b8
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    spoolsv.exe
Registry Keys Modified
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
    1601
    0x00000000
  • HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
    CurrentLevel
    0x00000000
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    ID
    0x48025ce1
Processes Created
  • c:\windows\system32\spoolsv.exe

download Try Sophos products for free
Download now