Backdoor Nitol – zmnfmc.exe – 203a71e8b2e6d39d9ad643aa1252a112

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Nitol
Also known as: Trojan Scar, Backdoor RBot
SHA256: 5fcbe6842d69f7ecd359dadb615731755c1deb83250f8dada8d8d5b75a557770
SHA1: 801026256928e0a9164480d9a33b1efe8392cfc2
MD5: 203a71e8b2e6d39d9ad643aa1252a112
File size: 29217 bytes

Created files:

%WinDir%\zmnfmc.exe – Backdoor Nitol

Backdoor Nitol created autostart registry keys:

HKLM\System\CurrentControlSet\Services\DSLserveryii\Type: 10000000
HKLM\System\CurrentControlSet\Services\DSLserveryii\Start: 02000000
HKLM\System\CurrentControlSet\Services\DSLserveryii\DisplayName: DCOM Serveribt Process Launcher.
HKLM\System\CurrentControlSet\Services\DSLserveryii\ImagePath: %WinDir%\zmnfmc.exe
HKLM\System\CurrentControlSet\Services\DSLserveryii\Description: DCOM Serverwry Process Launcher..

Leave a Reply