BKDR_AGENT.FBB
Entry created by this Malware:
Windows startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Ttool = “%Windows%\9129837.exe”
Windows NT, 2000, XP, and Server 2003
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\hide_evr2
ImagePath = “%Windows%\HIDE_EVR2.SYS”
DisplayName = “!!!!”
It will connect to this website
http://81.95.{BLOCKED}.107/cgi-bin/options.cgi
NOTE:Scan your computer every week
Tag:BKDR_AGENT.FBB


