Backdoor Nitol – gei33.dll – 0293a96452bacca4e05ad28bc0600b83

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Backdoor RBot, Trojan Downloader.Generic
SHA256: 893e4759261696a00ab58440888f38146a03b8e88940e57cd81904899ff27342
SHA1: 6787bfd2d42c70a906c9d553a2c2471cdc12af1e
MD5: 0293a96452bacca4e05ad28bc0600b83
File size: 50688 bytes

Created files:

%SysDir%\gei33.dll – Backdoor Nitol
%SysDir%\ooegos.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\stmwcysyyc\Type: 10000000
HKLM\System\CurrentControlSet\Services\stmwcysyyc\Start: 02000000
HKLM\System\CurrentControlSet\Services\stmwcysyyc\DisplayName: qpevikeffmznimkkasvw
HKLM\System\CurrentControlSet\Services\stmwcysyyc\ImagePath: %WinDir%\System32\ooegos.exe
HKLM\System\CurrentControlSet\Services\stmwcysyyc\Description: srenzkycxfxtlsgypsfadpooefxzbc

Leave a Reply