Backdoor Nitol – hra33.dll – fa616c0493824adf45df8441817938b9

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Worm AMN, Trojan Agent
SHA256: 66975b087f8c67ca6fb9c06675800901dc8c2b38b90d59307656cce592e667cf
SHA1: 7774658aa884314d1bc5ed7f536d99f4a66dadd3
MD5: fa616c0493824adf45df8441817938b9
File size: 47104 bytes

Created files:

%SysDir%\hra33.dll – Backdoor Nitol
%SysDir%\igayce.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribuaav\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribuaav\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribuaav\DisplayName: Distribuqxb Transaction Coordinator Service
HKLM\System\CurrentControlSet\Services\Distribuaav\ImagePath: %WinDir%\System32\igayce.exe
HKLM\System\CurrentControlSet\Services\Distribuaav\Description: Distribusda Transaction Coordinator Service.

Leave a Reply