Solved! Use NOTEPAB.EXE (Backdoor Zegost) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NOTEPAB.EXE – Backdoor Zegost removal

File MD5 Virus Alias
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Backdoor Zegost
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Trojan, Suspicious File
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Trojan Artemis
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Trojan Generic
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Trojan Eldorado
NOTEPAB.EXE 7a58e4347495c22512992abdd8ffbdb0 Trojan Downloader

NOTEPAB.EXE size: 386049 bytes
NOTEPAB.EXE hash: 7A58E4347495C22512992ABDD8FFBDB0

Created files:

C:\Windows\BJ.exe
C:\Windows\notepab.exe
C:\Windows\svchest000.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Kris: c:\Windows\notepab.exe

Detected by UnHackMe:

NOTEPAB.EXE
Default location: %WinDir%\NOTEPAB.EXE

Dropper information:
MD5: 7a58e4347495c22512992abdd8ffbdb0
File size: 386049 bytes

Leave a Reply