1919.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

1919.EXE – Backdoor Nitol removal

FileMD5Virus Alias
1919.EXE 209b2237ac475b48a751f3e89f484f3b Backdoor Nitol
1919.EXE 209b2237ac475b48a751f3e89f484f3b Suspicious File
1919.EXE 209b2237ac475b48a751f3e89f484f3b Trojan Eldorado
1919.EXE 209b2237ac475b48a751f3e89f484f3b Backdoor RBot
1919.EXE 209b2237ac475b48a751f3e89f484f3b Trojan Downloader
1919.EXE 209b2237ac475b48a751f3e89f484f3b Trojan Graftor

1919.EXE size: 64512 bytes
1919.EXE hash: 209B2237AC475B48A751F3E89F484F3B

Created files:

%WinDir%\alws.exe
%SysDir%\ssmgss.exe
%TEMP%\123.exe
%TEMP%\1919.exe
%WinDir%\zip.dll

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\alws: %WinDir%\alws.exe
HKLM\System\CurrentControlSet\Services\oxoddos\Type: 10000000
HKLM\System\CurrentControlSet\Services\oxoddos\Start: 02000000
HKLM\System\CurrentControlSet\Services\oxoddos\DisplayName: oxoddos
HKLM\System\CurrentControlSet\Services\oxoddos\ImagePath: %WinDir%\System32\ssmgss.exe
HKLM\System\CurrentControlSet\Services\oxoddos\Description: oxoddos

Detected by UnHackMe:

1919.EXE
Default location: %TEMP%\1919.EXE

Dropper information:
MD5: 03a49762698a3c3bb03317818f232b02
File size: 371712 bytes

Leave a Reply