New SpyFalcon variant
New SpyFalcon variant found today as well: C:\Windows\System32\higjxe.dll
Reg keys for C:\Windows\System32\higjxe.dll:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{a0c51615-738a-4542-801a-5af61614e182}”=”bedimples”
[HKEY_CURRENT_USER\Software\Classes\CLSID\
{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@=”C:\\WINDOWS\\system32\\higjxe.dll”
SpyFalcon removal guide updated.
Security news and information


