GEI33.DLL – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

GEI33.DLL – Backdoor Nitol removal

FileMD5Virus Alias
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Backdoor Nitol
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Trojan Generic
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Backdoor RBot
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Trojan Downloader
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Trojan Graftor
GEI33.DLL 655d12e373b5891981111e48da1f0a88 Worm Autorun

GEI33.DLL size: 9728 bytes
GEI33.DLL hash: 655D12E373B5891981111E48DA1F0A88

Created files:

%SysDir%\gei33.dll
%SysDir%\qywquy.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\netscvre\Type: 10000000
HKLM\System\CurrentControlSet\Services\netscvre\Start: 02000000
HKLM\System\CurrentControlSet\Services\netscvre\DisplayName: NT LM Security Support Providers
HKLM\System\CurrentControlSet\Services\netscvre\ImagePath: %WinDir%\System32\qywquy.exe
HKLM\System\CurrentControlSet\Services\netscvre\Description: NT LM Security Support Providers

Detected by UnHackMe:

GEI33.DLL
Default location: %SYSDIR%\GEI33.DLL

Dropper information:
MD5: 0be7dc69e5f1f45bc941aa48c270f1b4
File size: 49664 bytes

Leave a Reply