Solved! Use KOUSOE.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

KOUSOE.EXE – Backdoor Nitol removal

File MD5 Virus Alias
KOUSOE.EXE b0e6b093fc9f0b4c500a7ff1441682a9 Backdoor Nitol
KOUSOE.EXE b0e6b093fc9f0b4c500a7ff1441682a9 Trojan SuspiciousFile
KOUSOE.EXE b0e6b093fc9f0b4c500a7ff1441682a9 Trojan Artemis
KOUSOE.EXE b0e6b093fc9f0b4c500a7ff1441682a9 Trojan Generic
KOUSOE.EXE b0e6b093fc9f0b4c500a7ff1441682a9 Backdoor Farfli

KOUSOE.EXE size: 19968 bytes
KOUSOE.EXE hash: B0E6B093FC9F0B4C500A7FF1441682A9

Created files:

%WinDir%\kousoe.exe
%SysDir%\hra33.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\Type: 10010000
HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\Start: 02000000
HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\DisplayName: Bcdefg Ijklmnop Rstuvwxy Bcde
HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\ImagePath: %WinDir%\kousoe.exe
HKLM\System\CurrentControlSet\Services\Bcdefg Ijklmnop Rst\Description: Bcdefghi Klmnopqrs Uvwxyab Defghijk Mno

Detected by UnHackMe:

KOUSOE.EXE
Default location: %WinDir%\KOUSOE.EXE

Dropper information:
MD5: b0e6b093fc9f0b4c500a7ff1441682a9
File size: 19968 bytes

Leave a Reply