COUWKS.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

COUWKS.EXE – Backdoor Nitol removal

FileMD5Virus Alias
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Backdoor Nitol
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Trojan SuspiciousFile
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Trojan Artemis
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Trojan Hllw
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Trojan Eldorado
COUWKS.EXE 83c427288ea5319dcda5e4d6504c2fe9 Trojan Downloader

COUWKS.EXE size: 50688 bytes
COUWKS.EXE hash: 83C427288EA5319DCDA5E4D6504C2FE9

Created files:

%SysDir%\couwks.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationalahf\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationalahf\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationalahf\DisplayName: Nationalvps Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationalahf\ImagePath: %WinDir%\System32\couwks.exe
HKLM\System\CurrentControlSet\Services\Nationalahf\Description: Providesqgu a domain server for NI security.

Detected by UnHackMe:

COUWKS.EXE
Default location: %SYSDIR%\COUWKS.EXE

Dropper information:
MD5: 83c427288ea5319dcda5e4d6504c2fe9
File size: 50688 bytes

Leave a Reply