Associated Malware Groups
The filename is associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
RKFO.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Disables the Built in Windows System Restore Feature
- Executes Processes stored in Temporary Folders
- This process creates other processes on disk
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- This Process Deletes Other Processes From Disk
- Installs a browser helper object (BHO)
- Injects code into other processes
- Registers a Dynamic Link Library File
- Found on infected systems and resists interrogation by security products
- Creates new folders on the system
- Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
- Terminates Processes
RKFO.EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Deleted as a process from disk
- Executed from Temporary Folders
- Copied to multiple locations on the system
Country Of Origin
The filename RKFO.EXE was first seen on Feb 5 2010 in the following geographical regions of the Prevx community:
- Argentina on Feb 5 2010
- The United Kingdom on Feb 5 2010
- The United States on Feb 5 2010
- Korea, Republic of on Feb 8 2010
File Name Aliases
RKFO.EXE can also use the following file names:
- GCOIU.EXE
- DQCCPNQ.EXE
- YLJXSDN.EXE
- FSFAKJ.EXE
- GSWFYGXM.EXE
- IQMJE.EXE
- JIYXFPG.EXE
- XBXPI.EXE
- AOJFTSSG.EXE
- PIPNIBG.EXE
- OATZJ[1].HTM
- VKYUVU.EXE
- ATDVTF.EXE
- CCBLP[1].HTM
- ULHQ.EXE
- SWFMBL.EXE
- WYROP.EXE
- SKTNA.EXE
- EOFR.EXE
- MPGMRC.EXE
- NBJAOR.EXE
- QIKAOI.EXE
- HYXRMXS[1].HTM
- HHDL.EXE
- QDRUOFP.EXE
- MXSIMJN.EXE
- TDKBVYQ.EXE
- SSNMEFXR.EXE
- CRXT.EXE
- UGJHRPE.EXE
- WMHJEBK.EXE
- HBEYGM.EXE
- RGXC.EXE
- LNWPKLIR.EXE
- WCYIJJT[1].HTM
- RVSUKT.EXE
- QXTAQICC.EXE
- QRIG.EXE
- MMPMEGX.EXE
- WNZIP32.EXE
- ODNIIMY.EXE
- JYONUP.EXE
- IEXEYN.EXE
- MTYLPCJ.EXE
- AUTORUN.EXE
- UXDNNNO[1].HTM
- 31779686.DAT
Filesizes
The following file size has been seen:
- 137,216 bytes
- 37,888 bytes
- 100,972 bytes
- 117,248 bytes
- 274,439 bytes
File Type
The filename RKFO.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.