EXPLORER.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

EXPLORER.EXE – Backdoor Nitol removal

FileMD5Virus Alias
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Backdoor Nitol
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Trojan SuspiciousFile
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Trojan Artemis
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Trojan Generic
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Trojan Downloader
EXPLORER.EXE a98649a774484c52040ef48999bb06b7 Trojan CI

EXPLORER.EXE size: 347760 bytes
EXPLORER.EXE hash: A98649A774484C52040EF48999BB06B7

Created files:

%SysDir%\explorer.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribuiwg\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribuiwg\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribuiwg\DisplayName: Distribuaqj Transaction Coordinator Service.
HKLM\System\CurrentControlSet\Services\Distribuiwg\ImagePath: %WinDir%\System32\explorer.exe

Detected by UnHackMe:

EXPLORER.EXE
Default location: %SYSDIR%\EXPLORER.EXE

Dropper information:
MD5: a98649a774484c52040ef48999bb06b7
File size: 347760 bytes

Leave a Reply