IQEEQJY.EXE – Backdoor Farfli

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

IQEEQJY.EXE – Backdoor Farfli removal

FileMD5Virus Alias
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Backdoor Farfli
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Trojan Generic
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Trojan Eldorado
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Trojan Downloader
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Trojan Agent
IQEEQJY.EXE 0b450f47de556a10e209db066c74143a Backdoor Zegost

IQEEQJY.EXE size: 253952 bytes
IQEEQJY.EXE hash: 0B450F47DE556A10E209DB066C74143A

Created files:

%WinDir%\Iqeeqjy.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Rudfki oizssaus\ReleiceName: Ywsmwc qeqeka
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\ConnectGroup: ??????
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\MarkTime: 2013-03-19 04:43
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\Type: 10010000
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\Start: 02000000
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\DisplayName: Rpexvx etkufuvv
HKLM\System\CurrentControlSet\Services\Ywsmwc qeqeka\ImagePath: %WinDir%\Iqeeqjy.exe

Detected by UnHackMe:

IQEEQJY.EXE
Default location: %WinDir%\IQEEQJY.EXE

Dropper information:
MD5: 0b450f47de556a10e209db066c74143a
File size: 253952 bytes

Leave a Reply