Solved! Use TCZNMQ.EXE (Rootkit TDSS) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TCZNMQ.EXE – Rootkit TDSS removal

FileMD5Virus Alias
TCZNMQ.EXE ca83d301ce7c37ec11d6438cb6bdefaf Rootkit TDSS
TCZNMQ.EXE ca83d301ce7c37ec11d6438cb6bdefaf Trojan SuspiciousFile
TCZNMQ.EXE ca83d301ce7c37ec11d6438cb6bdefaf Trojan Artemis
TCZNMQ.EXE ca83d301ce7c37ec11d6438cb6bdefaf Trojan Generic
TCZNMQ.EXE ca83d301ce7c37ec11d6438cb6bdefaf Trojan Downloader

TCZNMQ.EXE size: 82540 bytes
TCZNMQ.EXE hash: CA83D301CE7C37EC11D6438CB6BDEFAF

Created files:

%WinDir%\tcznmq.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Type: 10010000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Start: 02000000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\DisplayName: Jklmno Qrstuvwx Abcdefgh Jklm
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\ImagePath: %WinDir%\tcznmq.exe
HKLM\System\CurrentControlSet\Services\Jklmno Qrstuvwx Abc\Description: Jklmnopq Stuvwxyab Defghij Lmnopqrs Uvw

Detected by UnHackMe:

TCZNMQ.EXE
Default location: %WinDir%\TCZNMQ.EXE

Dropper information:
MD5: ca83d301ce7c37ec11d6438cb6bdefaf
File size: 82540 bytes

Leave a Reply