Trojan Jorik – mt6fbecm.dll – bafd052b613cbc8d636898de8fc4f42a

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Jorik
Also known as: Backdoor Farfli, Trojan Agent
SHA256: 944a839338e0aef1a5508f8e67b56931e356b979b3c2d01c5c939227cac4d57b
SHA1: f2596a363ee9d5b7a6b96c003dae7771b8c3a4f6
MD5: bafd052b613cbc8d636898de8fc4f42a
File size: 344064 bytes

Created files:

%SysDir%\mt6fbecm.dll – Trojan Jorik

Trojan Jorik created autostart registry keys:

HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Type: 20010000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Start: 02000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\DisplayName: xxx_ServiceDisplayName
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\ImagePath: %SystemRoot%\System32\svchost.exe -k “xxiaoxiliushui”
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C006D007400360066006200650063006D002E0064006C006C000000
HKLM\System\CurrentControlSet\Services\xxiaoxiliushui\Parameters\ServiceMain: BBEE

Leave a Reply