Solved! Use EEEAEA.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

EEEAEA.EXE – Backdoor Nitol removal

File MD5 Virus Alias
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Backdoor Nitol
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Trojan SuspiciousFile
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Trojan ModifiedUPX
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Trojan PAK_Generic
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Trojan Generic
EEEAEA.EXE 2c696cd8500577f4a2254857c0a0b374 Trojan Eldorado

EEEAEA.EXE size: 17920 bytes
EEEAEA.EXE hash: 2C696CD8500577F4A2254857C0A0B374

Created files:

%SysDir%\eeeaea.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\aspnet_states\Type: 10000000
HKLM\System\CurrentControlSet\Services\aspnet_states\Start: 02000000
HKLM\System\CurrentControlSet\Services\aspnet_states\DisplayName: ASP.NET State Services
HKLM\System\CurrentControlSet\Services\aspnet_states\ImagePath: %WinDir%\System32\eeeaea.exe
HKLM\System\CurrentControlSet\Services\aspnet_states\Description: Provides support for out-of-to-process

Detected by UnHackMe:

EEEAEA.EXE
Default location: %SYSDIR%\EEEAEA.EXE

Dropper information:
MD5: 2c696cd8500577f4a2254857c0a0b374
File size: 17920 bytes

Leave a Reply