Home Malware Programs Trojans Gargafx

Gargafx

Posted: March 28, 2006

Gargafx is a trojan that executes potentially harmful arbitrary files secretly downloaded from a predetermined web server. The spyware hides its presence in the computer by injecting malicious code into legitimate computer processes. Gargafx is able to automatically reinstall itself. The threat runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winstats.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOncewinstatsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinstats
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}0ADAAE1B-6BD2-6CE0-1AA3-8DAB6CDE2EBC
Loading...