Solved! Use DQLPQG.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DQLPQG.EXE – Backdoor Nitol removal

File MD5 Virus Alias
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Backdoor Nitol
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Trojan SuspiciousFile
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Trojan Artemis
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Trojan Eldorado
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Trojan Downloader
DQLPQG.EXE 61eccd4258fa6a31dad9bce6def11c3d Trojan Graftor

DQLPQG.EXE size: 50176 bytes
DQLPQG.EXE hash: 61ECCD4258FA6A31DAD9BCE6DEF11C3D

Created files:

%SysDir%\dqlpqg.exe
%SysDir%\gei33.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\xhatmuudqb\Type: 10000000
HKLM\System\CurrentControlSet\Services\xhatmuudqb\Start: 02000000
HKLM\System\CurrentControlSet\Services\xhatmuudqb\DisplayName: hmknhfxaxqxkjlzzqtsj
HKLM\System\CurrentControlSet\Services\xhatmuudqb\ImagePath: %WinDir%\System32\dqlpqg.exe
HKLM\System\CurrentControlSet\Services\xhatmuudqb\Description: faeedfuujkolxjoqkdvfepvlhvhrwt

Detected by UnHackMe:

DQLPQG.EXE
Default location: %SYSDIR%\DQLPQG.EXE

Dropper information:
MD5: 61eccd4258fa6a31dad9bce6def11c3d
File size: 50176 bytes

Leave a Reply