Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

FJPARK8.EXE is Backboor Gurl.2

$
0
0

The file FJPARK8.EXE is a computer worm.
The worm FJPARK8.EXE is a self-replicating malicious program,
which uses a computer network to send copies of itself to other computers.
You must fix the FJPARK8.EXE problem as soon as possible!
Delete the file FJPARK8.EXE from all infected computers in your network.
Set up your network firewall against FJPARK8.EXE intervention.

Malware Analysis of FJPARK8.EXE
Full path on a computer: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe

Detected by UnHackMe:

Item Name: shell
Author: Unknown
Related File: explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe
Type: User Shell

Item Name: taskman
Author: Unknown
Related File: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\FJPARK8.EXE
Type: Winlogon System

Item Name: fjpark9
Author: Unknown
Related File: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\FJPARK8.EXE
Type: Registry Run

Item Name: FJPARK8.EXE
Author: Unknown
Related File: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\FJPARK8.EXE
Type: Multi AV Detected Files

Removal Results: Success
Number of reboot: 1

FJPARK8.EXE is known as:

Backboor.Gurl.2, Trojan.Agent.aaxv (v), Troj.Agent-AAXV, Backdoor.Azbreg.bqi, Trj.Zbot.M, Trojan.Lethic.B, Trojan.Agent.Gen-IRCBot, Trojan.HmBlocker, W32.Trojan.WLUI-7811, BScope.Backdoor.IRCBot.2122, Win32.Injector.AEJX, Trojan.Ircbrute, W32.Injector.AEJX.tr

FJPARK8.EXE hash:

  • MD5: 4cca12bea488186194717b7b122329b8
The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
How to quickly detect FJPARK8.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe”
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\fjpark9: “C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe”
  • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe”
Folders:
  • C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509
Files:
  • C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\Desktop.ini
  • C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-85509\fjpark8.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>