Solved! Use CGSGGG.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CGSGGG.EXE – Backdoor Nitol removal

FileMD5Virus Alias
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Backdoor Nitol
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Trojan, Suspicious File
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Trojan Artemis
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Trojan Eldorado
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Trojan Downloader
CGSGGG.EXE 3787c9d312b078bfa83b160a173d7e6e Trojan Agent

CGSGGG.EXE size: 18432 bytes
CGSGGG.EXE hash: 3787C9D312B078BFA83B160A173D7E6E

Created files:

%WinDir%\cgsggg.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\.Net CLR\Type: 10010000
HKLM\System\CurrentControlSet\Services\.Net CLR\Start: 02000000
HKLM\System\CurrentControlSet\Services\.Net CLR\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\.Net CLR\DisplayName: Microsoft .Net Framework COM+ Support
HKLM\System\CurrentControlSet\Services\.Net CLR\ImagePath: %WinDir%\cgsggg.exe
HKLM\System\CurrentControlSet\Services\.Net CLR\Description: Microsoft .NET COM+ Integration with SOAP

Detected by UnHackMe:

CGSGGG.EXE
Default location: %WinDir%\CGSGGG.EXE

Dropper information:
MD5: 3787c9d312b078bfa83b160a173d7e6e
File size: 18432 bytes

Leave a Reply