Backdoor Farfli – mt18065em.dll – be1dced3b0f4c19c9b2084dc51991dda

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Farfli
Also known as: Trojan Generic.KD, Trojan Agent
SHA256: 961931248be247761fd6f08439b025d6e4d240dd3642dc2b86ba41443f99b2e5
SHA1: 9b1710707ac24781bfe2da207fffaea892dbc9b3
MD5: be1dced3b0f4c19c9b2084dc51991dda
File size: 290816 bytes

Created files:

%SysDir%\mt18065em.dll – Backdoor Farfli

Backdoor Farfli created autostart registry keys:

HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Type: 20010000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Start: 02000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\DisplayName: xxx_ServiceDisplayName
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\ImagePath: %SystemRoot%\System32\svchost.exe -k “xxiaoxiliushui”
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C006D0074003100380030003600350065006D002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Parameters\ServiceMain: BBEE

Leave a Reply