Solved! Use TGFRGM.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TGFRGM.EXE – Backdoor Nitol removal

FileMD5Virus Alias
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Backdoor Nitol
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Trojan PcClient
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Trojan SuspiciousFile
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Trojan Generic
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Trojan MulDrop4
TGFRGM.EXE 424b42bbe9c965d91b2445496292f262 Trojan Eldorado

TGFRGM.EXE size: 41472 bytes
TGFRGM.EXE hash: 424B42BBE9C965D91B2445496292F262

Created files:

%SysDir%\tgfrgm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribuwxt\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribuwxt\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribuwxt\DisplayName: Distribubkc Transaction Coordinator Service
HKLM\System\CurrentControlSet\Services\Distribuwxt\ImagePath: %WinDir%\System32\tgfrgm.exe

Detected by UnHackMe:

TGFRGM.EXE
Default location: %SYSDIR%\TGFRGM.EXE

Dropper information:
MD5: 424b42bbe9c965d91b2445496292f262
File size: 41472 bytes

Leave a Reply