Home Malware Programs Trojans Fgbot

Fgbot

Posted: March 28, 2006

Fgbot is a trojan that contacts a predetermined web server in order to receive specific instructions that describe spyware's behavior. The threat can silently download from the Internet, install and run malicious software, block access to certain web sites or send the web browser to undesirable resources. Fgbot automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dotcfg.dll
    2 fgsrv2.dll
    3 fsrv.dll
    4 phffg.dll
    5 rufg.exe
    6 ulffg.dll
    7 upfg.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTCLSID[randomname]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsfgcommentHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsfgidHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsfgnoinstallHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsfgrunfromHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsfgversionHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingssizeofformlogfileHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce[X]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadfgsrv
Loading...