fairm010 Posted March 14, 2014 Posted March 14, 2014 SEC has just flagged up to one of the machines having Mal/EncPk-AAK with the path C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb. Is this a cause for concern or a false positive, I cant find anything on the web at all!
kmount Posted March 16, 2014 Posted March 16, 2014 I'd just clean it / rebuild the machine. Plenty of mention of this particular infection on the internet suggesting it's legit so worth cleaning up and moving on.
psydii Posted March 16, 2014 Posted March 16, 2014 (edited) Looks like to this: http://www.sophos.com/en-us/support/knowledgebase/118310.aspx Also F Secure: have a similar article: http://www.f-secure.com/v-descs/other_w32_generic.shtml I'm pretty sure that this is a false positive. A Trojan is unlikely to be trying to hide out as a JET database.... That is more of an APT style subterfuge. Edited March 16, 2014 by psydii 2
fairm010 Posted March 16, 2014 Author Posted March 16, 2014 I was convinced it was a false pos but thought I'd ask. I'll probably just re image anyway.
synaesthesia Posted March 16, 2014 Posted March 16, 2014 tmp.edb in that location is legitimate - I would hazard a guess at being part of the windows search indexing system. False positive, don't rebuild; you'll be rebuilding *all* your systems if you check anything on win7+ for that file!
Alis_Klar Posted June 29, 2015 Posted June 29, 2015 Got this on weekly scan. Interesting that it found in 2Simple Collection. Really annoys me that sophos info pages about viruses invariably are devoid of any usefull information. File "C:\Program Files (x86)\2Simple Software\2Simple collection\2Type\Admin Settings\reportTool.exe" belongs to virus/spyware 'Mal/EncPk-AAK'. Registry value "HKU\S-1-5-21-555032959-2862063602-2195562804-3888\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun" belongs to virus/spyware 'Mal/EncPk-AAK'. Registry value "HKU\S-1-5-21-555032959-2862063602-2195562804-3613\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun" belongs to virus/spyware 'Mal/EncPk-AAK'. Virus/spyware 'Mal/EncPk-AAK' has been removed.
fairm010 Posted June 29, 2015 Author Posted June 29, 2015 I'm getting it on more than just the tmp.edb. Getting it on various other bits of software now!
psydii Posted June 29, 2015 Posted June 29, 2015 (edited) Have you submitted samples to Sophos for evaluation? At the very least it should help them tweak the detection to avoid the false positive. Also here is an update to recommended exclusions, with a copy-paste list (it's so easy now to import into Sophos!) http://configmgrblog.com/2012/05/09/anti-virus-scan-exclusions-for-configuration-manager-2012/ Edited June 29, 2015 by psydii
psydii Posted June 29, 2015 Posted June 29, 2015 https://www.sophos.com/en-us/support/knowledgebase/11490.aspx
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now