CSSMOE.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CSSMOE.EXE – Backdoor Nitol removal

FileMD5Virus Alias
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Backdoor Nitol
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Trojan Artemis
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Trojan Eldorado
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Backdoor RBot
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Trojan Downloader
CSSMOE.EXE c05f76a0d4c5a25487ab5ec545e8d742 Trojan Graftor

CSSMOE.EXE size: 66560 bytes
CSSMOE.EXE hash: C05F76A0D4C5A25487AB5EC545E8D742

Created files:

%SysDir%\cssmoe.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationaltmb\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationaltmb\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationaltmb\DisplayName: Nationalodo Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationaltmb\ImagePath: %WinDir%\System32\cssmoe.exe
HKLM\System\CurrentControlSet\Services\Nationaltmb\Description: Provideskph a domain server for NI security.

Detected by UnHackMe:

CSSMOE.EXE
Default location: %SYSDIR%\CSSMOE.EXE

Dropper information:
MD5: c05f76a0d4c5a25487ab5ec545e8d742
File size: 66560 bytes

Leave a Reply