Solved! Use JAXFAQ.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

JAXFAQ.EXE – Backdoor Nitol removal

File MD5 Virus Alias
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Backdoor Nitol
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Trojan Artemis
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Trojan Eldorado
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Backdoor RBot
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Trojan Downloader
JAXFAQ.EXE 473e13fc776ecf303d81909eaa58269d Trojan Agent

JAXFAQ.EXE size: 34304 bytes
JAXFAQ.EXE hash: 473E13FC776ECF303D81909EAA58269D

Created files:

%SysDir%\jaxfaq.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationalrue\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationalrue\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationalrue\DisplayName: Nationaltsi Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationalrue\ImagePath: %WinDir%\System32\jaxfaq.exe
HKLM\System\CurrentControlSet\Services\Nationalrue\Description: Providesynl a domain server for NI security.

Detected by UnHackMe:

JAXFAQ.EXE
Default location: %SYSDIR%\JAXFAQ.EXE

Dropper information:
MD5: 473e13fc776ecf303d81909eaa58269d
File size: 34304 bytes

Leave a Reply