Backdoor Nitol – hgzlcm.exe – d9146e5cd59048b4c160ec9da256f89b

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Trojan CI, Trojan Downloader.Generic
SHA256: 1b3d2fbb9641964c7084ae898df61da3fd00a1be2f76657c633c6485cbbdbcb4
SHA1: a39c6b810e456ff4b7426ee133cfd1177d71b485
MD5: d9146e5cd59048b4c160ec9da256f89b
File size: 40448 bytes

Created files:

%SysDir%\hgzlcm.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\eqtgjoparm\Type: 10000000
HKLM\System\CurrentControlSet\Services\eqtgjoparm\Start: 02000000
HKLM\System\CurrentControlSet\Services\eqtgjoparm\DisplayName: owzdqyoxytjbbhawdydc
HKLM\System\CurrentControlSet\Services\eqtgjoparm\ImagePath: %WinDir%\System32\hgzlcm.exe
HKLM\System\CurrentControlSet\Services\eqtgjoparm\Description: prjbxphoohpkwqyuhrqzhnbnfuvqnq

Leave a Reply