Solved! Use ICGTGRM.EXE (Backdoor Farfli) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ICGTGRM.EXE – Backdoor Farfli removal

FileMD5Virus Alias
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Backdoor Farfli
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Trojan SuspiciousFile
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Trojan Generic
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Trojan Kazy
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Trojan Agent
ICGTGRM.EXE b834d6a8a2df1504d53804c67524c25b Backdoor Zegost

ICGTGRM.EXE size: 109568 bytes
ICGTGRM.EXE hash: B834D6A8A2DF1504D53804C67524C25B

Created files:

%Program Files%\Ruiwod ktggy\Icgtgrm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Coqewy aamqka\ConnectGroup: ????1433
HKLM\System\CurrentControlSet\Services\Coqewy aamqka\MarkTime: 2014-11-20 23:50
HKLM\System\CurrentControlSet\Services\Coqewy aamqka\Type: 10010000
HKLM\System\CurrentControlSet\Services\Coqewy aamqka\Start: 02000000
HKLM\System\CurrentControlSet\Services\Coqewy aamqka\DisplayName: Eaogmq kyayqaas
HKLM\System\CurrentControlSet\Services\Coqewy aamqka\ImagePath: %Program Files%\Ruiwod ktggy\Icgtgrm.exe
HKLM\System\CurrentControlSet\Services\Ruokfa xzgmescn\ReleiceName: Coqewy aamqka

Detected by UnHackMe:

ICGTGRM.EXE
Default location: %PROGRAM FILES%\RUIWOD KTGGY\ICGTGRM.EXE

Dropper information:
MD5: b834d6a8a2df1504d53804c67524c25b
File size: 109568 bytes

Leave a Reply