SVHOST.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVHOST.EXE – Backdoor Nitol removal

File MD5 Virus Alias
SVHOST.EXE 1a120da7409c14f75ebfd3b75ba44208 Backdoor Nitol
SVHOST.EXE 1a120da7409c14f75ebfd3b75ba44208 Trojan Artemis
SVHOST.EXE 1a120da7409c14f75ebfd3b75ba44208 Trojan Click
SVHOST.EXE 1a120da7409c14f75ebfd3b75ba44208 Backdoor Zegost

SVHOST.EXE size: 86016 bytes
SVHOST.EXE hash: 1A120DA7409C14F75EBFD3B75BA44208

Created files:

%SysDir%\hra33.dll
%SysDir%\svhost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Plase Input Service Nxnx\Type: 10010000
HKLM\System\CurrentControlSet\Services\Plase Input Service Nxnx\Start: 02000000
HKLM\System\CurrentControlSet\Services\Plase Input Service Nxnx\DisplayName: Please Input Sevice Dispdvb Transaction Coordinator Service
HKLM\System\CurrentControlSet\Services\Plase Input Service Nxnx\ImagePath: %WinDir%\System32//svhost.exe

Detected by UnHackMe:

SVHOST.EXE
Default location: %SYSDIR%\SVHOST.EXE

Dropper information:
MD5: 1a120da7409c14f75ebfd3b75ba44208
File size: 86016 bytes