Solved! Use BEFNAS.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

BEFNAS.EXE – Backdoor Nitol removal

File MD5 Virus Alias
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Backdoor Nitol
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Trojan SuspiciousFile
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Trojan Artemis
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Trojan Generic
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Trojan Eldorado
BEFNAS.EXE b0b8aae5e0d357b49ec667f05d6536c0 Backdoor RBot

BEFNAS.EXE size: 36352 bytes
BEFNAS.EXE hash: B0B8AAE5E0D357B49EC667F05D6536C0

Created files:

%SysDir%\befnas.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationalcjh\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationalcjh\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationalcjh\DisplayName: Nationaldgu Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationalcjh\ImagePath: %WinDir%\System32\befnas.exe
HKLM\System\CurrentControlSet\Services\Nationalcjh\Description: Provideslir a domain server for NI security.

Detected by UnHackMe:

BEFNAS.EXE
Default location: %SYSDIR%\BEFNAS.EXE

Dropper information:
MD5: b0b8aae5e0d357b49ec667f05d6536c0
File size: 36352 bytes

Leave a Reply