Solved! Use EGJFQO.EXE (Rootkit TDSS) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

EGJFQO.EXE – Rootkit TDSS removal

File MD5 Virus Alias
EGJFQO.EXE 0e9e86f447734edd4479e191fd00f5c9 Rootkit TDSS
EGJFQO.EXE 0e9e86f447734edd4479e191fd00f5c9 Trojan SuspiciousFile
EGJFQO.EXE 0e9e86f447734edd4479e191fd00f5c9 Trojan Artemis
EGJFQO.EXE 0e9e86f447734edd4479e191fd00f5c9 Trojan Generic
EGJFQO.EXE 0e9e86f447734edd4479e191fd00f5c9 Trojan Downloader

EGJFQO.EXE size: 73330 bytes
EGJFQO.EXE hash: 0E9E86F447734EDD4479E191FD00F5C9

Created files:

%WinDir%\egjfqo.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Type: 10010000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Start: 02000000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\DisplayName: Jklmno Qrstuvwx Abcdefgh Jklm
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\ImagePath: %WinDir%\egjfqo.exe
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Description: Jklmnopq Stuvwxyab Defghij Lmnopqrs Uvw

Detected by UnHackMe:

EGJFQO.EXE
Default location: %WinDir%\EGJFQO.EXE

Dropper information:
MD5: 0e9e86f447734edd4479e191fd00f5c9
File size: 73330 bytes

Leave a Reply