Home Malware Programs Trojans Mal/EncPk-AO

Mal/EncPk-AO

Posted: November 13, 2009

Mal/EncPk-AO is another malicious Trojan that may represent security risk for a compromised PC system or a network environment. Mal/EncPk-AO should not be taken lightly and contains characteristics of a severe security risk. Mal/EncPk-AO penetrates the system without the user's knowledge or permission and easily contacts a remote server to download other harmful parasites and malware onto the infected computer. Symptoms include your computer screen flipping upside down or inverting and documents or messages printing on your printer by themselves. For the safety of your computer, Mal/EncPk-AO should immediately be removed.

Aliases

Virus.Trojan.Win32.Pakes (Ikarus)
Win32/MalPackedB.suspicious (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Profiles%\Default User\Local Settings\Application Data\QQPlug\ClickLoadDrv.dll
    2 %Profiles%\Default User\Local Settings\Application Data\QQPlug\Img\Mini\dbty.png
    3 %Profiles%\Default User\Local Settings\Application Data\QQPlug\Img\Mini\QQMini.png

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}%Profiles%\Default User\Local Settings\Application Data\QQPlug%Profiles%\Default User\Local Settings\Application Data\QQPlug\Img%Profiles%\Default User\Local Settings\Application Data\QQPlug\Img\Mini%Profiles%\Default User\Local Settings\Application Data\QQPlug\Img\PopMsg%Profiles%\Default User\Local Settings\Application Data\QQPlug\Img\SysMsg
Loading...