afpkgr.exe

Crime Watch

Great Apps

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application afpkgr.exe by Great Apps has been detected as adware by 10 anti-malware scanners.
Publisher:
Great Apps  (signed and verified)

Product:
Crime Watch

Description:
CrimeWatch

Version:
1.0.0.0

MD5:
e1a7b3a5b45774694d7c9791fbdb1283

SHA-1:
013f4dd56e7e81a7a9959c38c4964b981aac0e39

SHA-256:
b8e7e78b0658f4837c5a154d92ba37b761bfabd9d46767b47b8aa0b9762f65c7

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/18/2024 7:39:23 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3135

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15419

Bkav FE
W64.HfsAdware
1.3.0.6379

Dr.Web
Adware.Yontoo.68
9.0.1.05190

ESET NOD32
MSIL/Adware.PullUpdate.N.gen application
7.0.302.0

Kaspersky
not-a-virus:AdWare.MSIL.PullUpdate
15.0.0.543

Malwarebytes
PUP.Optional.CrimeWatch.A
v2015.04.19.05

NANO AntiVirus
Trojan.Win64.Downware.dhdcgg
0.30.16.1110

Reason Heuristics
Threat.Injekt.GreatApps
15.4.19.0

Trend Micro House Call
TROJ_GEN.R0C1H05DI15
7.2.109

File size:
48.5 KB (49,624 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Great Apps 2015

Original file name:
CrimeWatch.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\application data\ynfctorwzwo\dat\afpkgr.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/16/2015 4:00:00 PM

Valid to:
2/17/2016 3:59:59 PM

Subject:
CN=Great Apps, O=Great Apps, L=St. Michael, S=St. Michael, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
18DA5D77283E42E4EA6279778229FFBA

File PE Metadata
Compilation timestamp:
4/17/2015 10:19:51 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:kgwiF0PpHmPzOlU/7yjFprM+L1rrpGClH:kDPpHmLOG/7UTJGCd

Entry address:
0xBE2E

Entry point:
48, A1, 00, 20, 00, 40, 00, 00, 00, 00, FF, E0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6226

Code size:
40 KB (40,960 bytes)

Remove afpkgr.exe - Powered by Reason Core Security