alf.dll
It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘avgnt’. The file has been seen being downloaded from doc-08-98-docs.googleusercontent.com.
MD5:
9459724659f53e35c6515ebe6c881c94
SHA-1:
4bc4949088ab9f84331d87dd9010f5a9a5a3b2b5
SHA-256:
2b0701b29c7e1d11eca756136d829abf8da1ed98a281735c06d870c9dffbe7d3
Scanner detections:
0 / 68
Status:
Clean (as of last analysis)
Analysis date:
5/6/2024 8:38:27 PM UTC (today)
File size:
688 KB (704,512 bytes)
File type:
Dynamic link library (Win64 DLL)
Common path:
C:\Program Files\steam\steamapps\downloading\8980\binaries\dlcsetup2\alf.dll
Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Command:
"C:\Program Files\avira\antivir desktop\avgnt.exe" \min
The file alf.dll has been seen being distributed by the following URL.