Backdoor Farfli – zgtbcm.exe – efb5f3b33c525309269b4b0aeb7391e3

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Farfli
Also known as: Trojan Downloader.Generic, Trojan Dialer
SHA256: 43f83b7cd36387475551531bb4cdb334bae58e047dc829272e63a9025a2f8fe7
SHA1: ac24c8bb9a1e8606192fbad99a66288dbf297777
MD5: efb5f3b33c525309269b4b0aeb7391e3
File size: 166400 bytes

Created files:

%SysDir%\zgtbcm.exe – Backdoor Farfli

Backdoor Farfli created autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\InitTime: 20120908
HKLM\System\CurrentControlSet\Services\BITS\Version: fnN8DBsWHCw=
HKLM\System\CurrentControlSet\Services\BITS\Group: 8Jj09Z3+/dMs
HKLM\System\CurrentControlSet\Services\DirectX Remover.\Type: 10010000
HKLM\System\CurrentControlSet\Services\DirectX Remover.\Start: 02000000
HKLM\System\CurrentControlSet\Services\DirectX Remover.\DisplayName: DirectX Remover for Windows(R).
HKLM\System\CurrentControlSet\Services\DirectX Remover.\ImagePath: %WinDir%\System32\zgtbcm.exe
HKLM\System\CurrentControlSet\Services\DirectX Remover.\Description: Microsoft(R) DirectX Remover for Windows(R).

Leave a Reply