Backdoor Nitol – hra33.dll – 2c48e56693239e9ca645c91f6e535106

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Trojan Downloader.Generic, Trojan FakeAV
SHA256: 102bb4d25a0301024efff07480241af4c61fc187dd84bcf405f84e149cac67a7
SHA1: 39ca54e7aba0b2ec004ca081a25cf5698c358cbb
MD5: 2c48e56693239e9ca645c91f6e535106
File size: 49664 bytes

Created files:

%SysDir%\hra33.dll – Backdoor Nitol
%SysDir%\swcssq.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\Yes777.CoM\Type: 10000000
HKLM\System\CurrentControlSet\Services\Yes777.CoM\Start: 02000000
HKLM\System\CurrentControlSet\Services\Yes777.CoM\DisplayName: Nationalihx Instruments BeT Service
HKLM\System\CurrentControlSet\Services\Yes777.CoM\ImagePath: %WinDir%\System32\swcssq.exe
HKLM\System\CurrentControlSet\Services\Yes777.CoM\Description: Providesqtf a bet server for NI security.

Leave a Reply