Solved! Use LKHLKM.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LKHLKM.EXE – Backdoor Nitol removal

File MD5 Virus Alias
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Backdoor Nitol
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Trojan SuspiciousFile
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Trojan Eldorado
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Backdoor RBot
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Trojan Downloader
LKHLKM.EXE b3229e13838004d04652684e26f0ab9a Trojan Agent

LKHLKM.EXE size: 56832 bytes
LKHLKM.EXE hash: B3229E13838004D04652684E26F0AB9A

Created files:

%SysDir%\lkhlkm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DSLserverhby\Type: 10000000
HKLM\System\CurrentControlSet\Services\DSLserverhby\Start: 02000000
HKLM\System\CurrentControlSet\Services\DSLserverhby\DisplayName: DCOM Serverwkr Process Launcher.
HKLM\System\CurrentControlSet\Services\DSLserverhby\ImagePath: %WinDir%\System32\lkhlkm.exe
HKLM\System\CurrentControlSet\Services\DSLserverhby\Description: DCOM Servernig Process Launcher..

Detected by UnHackMe:

LKHLKM.EXE
Default location: %SYSDIR%\LKHLKM.EXE

Dropper information:
MD5: b3229e13838004d04652684e26f0ab9a
File size: 56832 bytes

Leave a Reply