Solved! Use RIJJIQ.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RIJJIQ.EXE – Backdoor Nitol removal

File MD5 Virus Alias
RIJJIQ.EXE 566736c41467fb010b6905c124bbda4d Backdoor Nitol
RIJJIQ.EXE 566736c41467fb010b6905c124bbda4d Trojan Eldorado
RIJJIQ.EXE 566736c41467fb010b6905c124bbda4d Trojan Downloader
RIJJIQ.EXE 566736c41467fb010b6905c124bbda4d Trojan Agent
RIJJIQ.EXE 566736c41467fb010b6905c124bbda4d Backdoor Farfli

RIJJIQ.EXE size: 42496 bytes
RIJJIQ.EXE hash: 566736C41467FB010B6905C124BBDA4D

Created files:

%WinDir%\rijjiq.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\Type: 10010000
HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\Start: 02000000
HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\DisplayName: Defghi Klmnopqr Tuvwxyab Defg
HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\ImagePath: %WinDir%\rijjiq.exe
HKLM\System\CurrentControlSet\Services\Defghi Klmnopqr Tuv\Description: Defghijk Mnopqrstu Wxyabcd Fghijklm Opq

Detected by UnHackMe:

RIJJIQ.EXE
Default location: %WinDir%\RIJJIQ.EXE

Dropper information:
MD5: 566736c41467fb010b6905c124bbda4d
File size: 42496 bytes

Leave a Reply