Solved! Use SVCHSOT.EXE (Backdoor Farfli) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SVCHSOT.EXE – Backdoor Farfli removal

FileMD5Virus Alias
SVCHSOT.EXE 158cc220f5b72049611f3aed543dce61 Backdoor Farfli
SVCHSOT.EXE 158cc220f5b72049611f3aed543dce61 Trojan Eldorado
SVCHSOT.EXE 158cc220f5b72049611f3aed543dce61 Trojan Downloader
SVCHSOT.EXE 158cc220f5b72049611f3aed543dce61 Trojan Agent
SVCHSOT.EXE 158cc220f5b72049611f3aed543dce61 Backdoor Zegost

SVCHSOT.EXE size: 81920 bytes
SVCHSOT.EXE hash: 158CC220F5B72049611F3AED543DCE61

Created files:

%WinDir%\4931CC1E\svchsot.exe
%Temp%\bbx.exe
%Temp%\E_4\krnln.fnr

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\4931CC1E: %WinDir%\4931CC1E\svchsot.exe

Detected by UnHackMe:

SVCHSOT.EXE
Default location: %WinDir%\4931CC1E\SVCHSOT.EXE

Dropper information:
MD5: 7fbf8963ef5230ccdfa00978b18dc811
File size: 923772 bytes

Leave a Reply