Solved! Use TAFTWA.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

TAFTWA.EXE – Backdoor Nitol removal

File MD5 Virus Alias
TAFTWA.EXE ee2a92bed92d7d0758661fa979ca62fd Backdoor Nitol
TAFTWA.EXE ee2a92bed92d7d0758661fa979ca62fd Trojan SuspiciousFile
TAFTWA.EXE ee2a92bed92d7d0758661fa979ca62fd Trojan Eldorado
TAFTWA.EXE ee2a92bed92d7d0758661fa979ca62fd Trojan Downloader
TAFTWA.EXE ee2a92bed92d7d0758661fa979ca62fd Virus Sality

TAFTWA.EXE size: 108032 bytes
TAFTWA.EXE hash: EE2A92BED92D7D0758661FA979CA62FD

Created files:

%SysDir%\taftwa.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationalkkk\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationalkkk\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationalkkk\DisplayName: Nationalffc Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationalkkk\ImagePath: %WinDir%\System32\taftwa.exe
HKLM\System\CurrentControlSet\Services\Nationalkkk\Description: Providesbif a domain server for NI security.

Detected by UnHackMe:

TAFTWA.EXE
Default location: %SYSDIR%\TAFTWA.EXE

Dropper information:
MD5: ee2a92bed92d7d0758661fa979ca62fd
File size: 108032 bytes

Leave a Reply