Home Malware Programs Trojans FireFly

FireFly

Posted: March 28, 2006

FireFly is a trojan designed to contact predetermined web servers in order to silently download and execute arbitrary, potentially malicious files or install other spywares. It can also provide the attacker with unauthorized remote access to a compromised PC allowing the intruder to control the computer and steal user sensitive information. FireFly automatically runs as a service on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 delme.bat
    2 fireflyinfo.ini
    3 serpent.exe
    4 windebug.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesfirefly
Loading...