Threat Search: 

ThreatExpert's Statistics for Mal/EncPk-HW [Sophos]:

Mal/EncPk-HW [Sophos] is also known as:
Threat AliasNumber of Incidents
Generic Dropper.cx [McAfee]597
Trojan.Adclicker [Symantec]51
Virus.Win32.Rootkit [Ikarus]40
Trojan.Adclicker!sd6 [PC Tools]25
Trojan Horse [Symantec]18
TrojanDownloader:Win32/Renos.DY [Microsoft]18
FakeAlert-EL [McAfee]15
TrojanDownloader:Win32/Renos.DZ [Microsoft]15
Trojan.Dropper [Symantec]13
Win-Trojan/Xema.variant [AhnLab]11
Trojan.Win32.FraudPack [Ikarus]8
Backdoor.Trojan [Symantec]7
Infostealer [Symantec]7
Trojan-Downloader.Win32.Renos [Ikarus]7
Trojan.Win32.FraudPack.mqb [Kaspersky Lab]6
Trojan.Win32.FraudPack.mzb [Kaspersky Lab]5
Trojan-Dropper.Win32.Agent.apql [Kaspersky Lab]5
Trojan-Dropper.Win32.Agent.apqn [Kaspersky Lab]5
Downloader.MisleadApp [Symantec]4
FakeAlert-ET [McAfee]3
Suspicious.Skintrim [Symantec]3
Trojan.Renos [Ikarus]3
Trojan-Downloader.Win32.FraudLoad [Ikarus]3
Trojan-Downloader.Win32.FraudLoad.eil [Kaspersky Lab]3
Trojan-Dropper.Win32.Agent.aozo [Kaspersky Lab]3
TrojanDropper:Win32/Agent.EA [Microsoft]3
Downloader [Symantec]2
Packed.Win32.Katusha [Ikarus]2
Packed.Win32.Katusha.b [Kaspersky Lab]2
Trojan-Downloader.Win32.FraudLoad.edt [Kaspersky Lab]2
Trojan-Dropper.Agent [Ikarus]2
Win-Trojan/Fraudload.100356 [AhnLab]2
Win-Trojan/Katusha.99332 [AhnLab]2
Dropper/Agent.232964 [AhnLab]1
FakeAlert-FR [McAfee]1
FakeAlert-GV [McAfee]1
Generic Downloader.x!zo [McAfee]1
Generic Dropper.bw [McAfee]1
SpywareStrike [Symantec]1
TROJ_FAKEAL.CI [Trend Micro]1
TROJ_FRAUDPAC.JK [Trend Micro]1
Trojan.Crypt [Ikarus]1
Trojan.Fakealert [Ikarus]1
Trojan.Fakeavalert!gen [Symantec]1
Trojan.Win32.Agent.buws [Kaspersky Lab]1
Trojan.Win32.Agent.cghl [Kaspersky Lab]1
Trojan.Win32.Agent.cgwy [Kaspersky Lab]1
Trojan.Win32.Agent2 [Ikarus]1
Trojan.Win32.Agent2.kma [Kaspersky Lab]1
Trojan.Win32.FraudPack.nkl [Kaspersky Lab]1
Trojan.Win32.FraudPack.ogk [Kaspersky Lab]1
Trojan.Win32.FraudPack.ovr [Kaspersky Lab]1
Trojan.Win32.FraudPack.pbh [Kaspersky Lab]1
Trojan.Win32.FraudPack.pbi [Kaspersky Lab]1
Trojan.Win32.FraudPack.qzh [Kaspersky Lab]1
Trojan.Win32.Pakes.nne [Kaspersky Lab]1
Trojan:Win32/Meredrop [Microsoft]1
Trojan-Downloader.Win32.FraudLoad.evr [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.evt [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.fdb [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.wcyi [Kaspersky Lab]1
TrojanDownloader:Win32/Renos.GW [Microsoft]1
Win-Trojan/Agent.122884.D [AhnLab]1
Win-Trojan/Agent.183300 [AhnLab]1
Win-Trojan/Agent2.118276 [AhnLab]1
Win-Trojan/Fakeav.182276 [AhnLab]1
Win-Trojan/Fraudload.179204 [AhnLab]1
Win-Trojan/Fraudpack.120324 [AhnLab]1
Win-Trojan/Fraudpack.229892 [AhnLab]1
Win-Trojan/Pakes.185348 [AhnLab]1
Win-Trojan/Renos.120836.B [AhnLab]1
Win-Trojan/Renos.124416 [AhnLab]1
Win-Trojan/Renos.142340 [AhnLab]1
Win-Trojan/Renos.253444 [AhnLab]1
Win-Trojan/Zlob.92676 [AhnLab]1

Mal/EncPk-HW [Sophos] has the following possible country of origin:
OriginNumber of Incidents
China16

Mal/EncPk-HW [Sophos] is known to be created as:
%ProgramFiles%\target web ads\targetwebadsb.exe
%ProgramFiles%\target web ads\targetwebadsh.exe
%System%\090520-1-4.exe
%System%\090520-a-7.exe
%Temp%\090520-1-4.exe
%Temp%\090520-a-7.exe
%Temp%\090521-2-5.exe
%Temp%\090521-4-11.exe
%Temp%\090602-1-7.exe
%Temp%\090611-2-7.exe
%Temp%\090614-4-1.exe
%Temp%\a.exe
%Temp%\b.exe
%Temp%\c.exe
%Temp%\e.exe
%Windir%\msa.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.