Backdoor Nitol – gei33.dll – cf4b3a15b188f89590de81ac2f62fa58

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Trojan Downloader.Generic, Trojan Graftor
SHA256: ef06bc0c9f92a81182874dc05f381e5e0ffe5f3af084cea3f52f8ce3ff5783e0
SHA1: 6d64797bd1ae9910247de25b98a79d5015c8025c
MD5: cf4b3a15b188f89590de81ac2f62fa58
File size: 18944 bytes

Created files:

%SysDir%\gei33.dll – Backdoor Nitol
%SysDir%\rkrxcg.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Type: 10000000
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Start: 02000000
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\DisplayName: kvatxdknlyjyhfixjswn
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\ImagePath: %WinDir%\System32\rkrxcg.exe
HKLM\System\CurrentControlSet\Services\ncbxcoksfz\Description: kkufnuxxzrzbmnmgqooketlyhnkoau

Leave a Reply