Backdoor Farfli – kscan.exe – 38d09f1de51153488525f335900f02b6

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Farfli
Also known as: Backdoor Zegost, Backdoor Hupigon
SHA256: 9cc82dfa6d310460509275348d898c1d8433866ea2b8ee42a1e3710ddf767585
SHA1: 398366b1df7d496f80f96190b7b76974d59cc78a
MD5: 38d09f1de51153488525f335900f02b6
File size: 67072 bytes

Created files:

%SysDir%\kscan.exe – Backdoor Farfli

Backdoor Farfli created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run : %WinDir%\System32\kscan.exe
HKLM\System\CurrentControlSet\Services\Tianyu\Type: 10010000
HKLM\System\CurrentControlSet\Services\Tianyu\Start: 02000000
HKLM\System\CurrentControlSet\Services\Tianyu\DisplayName: Tianyu Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Tianyu\ImagePath: %WinDir%\System32\kscan.exe
HKLM\System\CurrentControlSet\Services\Tianyu\Description: Tianyu a domain server for NI security.

Leave a Reply