Backdoor Nitol – gei33.dll – 932f9536314a842d1cf5e4dd51bc666c

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Trojan CI, Trojan Scar
SHA256: ea2a3401e638c43bbf939ed8e2c2833885e2bd000d13f1a7e8f1cf3a51219e1a
SHA1: 7cc94e190150de17bfbf1cd84f92d717d6e85073
MD5: 932f9536314a842d1cf5e4dd51bc666c
File size: 48640 bytes

Created files:

%SysDir%\gei33.dll – Backdoor Nitol
%SysDir%\imgkme.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Type: 10000000
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Start: 02000000
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\DisplayName: kvatxdknlyjyhfixjswn
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\ImagePath: %WinDir%\System32\imgkme.exe
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Description: kkufnuxxzrzbmnmgqooketlyhnkoau

Leave a Reply