Solved! Use AEVEDQB.EXE (Backdoor Zegost) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

AEVEDQB.EXE – Backdoor Zegost removal

File MD5 Virus Alias
AEVEDQB.EXE 661574fa235cb6927670617f0924dae8 Backdoor Zegost
AEVEDQB.EXE 661574fa235cb6927670617f0924dae8 Trojan Agent
AEVEDQB.EXE 661574fa235cb6927670617f0924dae8 Trojan Jorik
AEVEDQB.EXE 661574fa235cb6927670617f0924dae8 Backdoor Farfli

AEVEDQB.EXE size: 15860224 bytes
AEVEDQB.EXE hash: 661574FA235CB6927670617F0924DAE8

Created files:

%WinDir%\Aevedqb.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\MarkTime: 2015-12-25 03:46
HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\Type: 10010000
HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\Start: 02000000
HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\DisplayName: Woooeo qyaayugc
HKLM\System\CurrentControlSet\Services\Emgscc eagqaa\ImagePath: %WinDir%\Aevedqb.exe
HKLM\System\CurrentControlSet\Services\Rucpdk kqvagyoo\ReleiceName: Emgscc eagqaa

Detected by UnHackMe:

AEVEDQB.EXE
Default location: %WinDir%\AEVEDQB.EXE

Dropper information:
MD5: c5d5a026b909ae6b1367fa4068ee3cd6
File size: 131584 bytes

Leave a Reply