Home Malware Programs Trojans Hirofu

Hirofu

Posted: March 28, 2006

Hirofu gathers user sensitive information, personal documents and other valuable data and sends it to the hacker by e-mail. The trojan has the ability to download and install additional malicious applications. Hirofu comes in randomly named files.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun[randomname]=C:DocumentsandSettings[CurrentUser]ApplicationData[executablewithrandomname]HKEY_CURRENT_USERSoftwareYasuhiroFuruta
Loading...