FEQUHKO.EXE – Backdoor Farfli

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

FEQUHKO.EXE – Backdoor Farfli removal

FileMD5Virus Alias
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Backdoor Farfli
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Trojan SuspiciousFile
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Trojan Artemis
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Trojan Generic
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Trojan Downloader
FEQUHKO.EXE 0ade8ff1fb46ecfe2385672bcfea7014 Trojan Comisproc

FEQUHKO.EXE size: 557172 bytes
FEQUHKO.EXE hash: 0ADE8FF1FB46ECFE2385672BCFEA7014

Created files:

%Program Files%\Ruyekf kgckb\Fequhko.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\MarkTime: 2013-07-02 04:57
HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\Type: 10010000
HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\Start: 02000000
HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\DisplayName: Cummiv apqqrkhl
HKLM\System\CurrentControlSet\Services\Mkemyo aayqca\ImagePath: %Program Files%\Ruyekf kgckb\Fequhko.exe
HKLM\System\CurrentControlSet\Services\Ruvjqq aqrqaupd\ReleiceName: Mkemyo aayqca

Detected by UnHackMe:

FEQUHKO.EXE
Default location: %PROGRAM FILES%\RUYEKF KGCKB\FEQUHKO.EXE

Dropper information:
MD5: 0ade8ff1fb46ecfe2385672bcfea7014
File size: 557172 bytes

Leave a Reply