Solved! Use ATIECLW.EXE (Backdoor Zegost) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

ATIECLW.EXE – Backdoor Zegost removal

File MD5 Virus Alias
ATIECLW.EXE 14e082b65e3dc5f0896bfe3f664f05e9 Backdoor Zegost
ATIECLW.EXE 14e082b65e3dc5f0896bfe3f664f05e9 Trojan Generic
ATIECLW.EXE 14e082b65e3dc5f0896bfe3f664f05e9 Trojan Downloader
ATIECLW.EXE 14e082b65e3dc5f0896bfe3f664f05e9 Trojan Agent
ATIECLW.EXE 14e082b65e3dc5f0896bfe3f664f05e9 Backdoor Farfli

ATIECLW.EXE size: 31723520 bytes
ATIECLW.EXE hash: 14E082B65E3DC5F0896BFE3F664F05E9

Created files:

%WinDir%\atieclw.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\.Net CLR\Type: 10010000
HKLM\System\CurrentControlSet\Services\.Net CLR\Start: 02000000
HKLM\System\CurrentControlSet\Services\.Net CLR\DisplayName: Microsoft .Net Framework COM+ Support
HKLM\System\CurrentControlSet\Services\.Net CLR\ImagePath: %WinDir%\atieclw.exe

Detected by UnHackMe:

ATIECLW.EXE
Default location: %WinDir%\ATIECLW.EXE

Dropper information:
MD5: 373aad323ac893233cd14c6fdea1a580
File size: 266240 bytes

Leave a Reply