Solved! Use SVCHOST.EXE (Backdoor Farfli) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Backdoor Farfli removal

File MD5 Virus Alias
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Backdoor Farfli
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Trojan Artemis
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Trojan XPACK
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Trojan Generic
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Trojan Downloader
SVCHOST.EXE adbeb22fb0476aa360c6481aa5bdf578 Worm Palevo

SVCHOST.EXE size: 77824 bytes
SVCHOST.EXE hash: ADBEB22FB0476AA360C6481AA5BDF578

Created files:

%Program Files Common%\svchost.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SVCSHOST: C:\progra~1\Common Files\svchost.exe
HKLM\System\CurrentControlSet\Services\BITS\InitTime: 20150414
HKLM\System\CurrentControlSet\Services\BITS\Version: +LXQs6Y=
HKLM\System\CurrentControlSet\Services\BITS\Group: tbqzs6Y=

Detected by UnHackMe:

SVCHOST.EXE
Default location: %PROGRAM FILES COMMON%\SVCHOST.EXE

Dropper information:
MD5: adbeb22fb0476aa360c6481aa5bdf578
File size: 77824 bytes

Leave a Reply