GKWIKM.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

GKWIKM.EXE – Backdoor Nitol removal

FileMD5Virus Alias
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Backdoor Nitol
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Trojan SuspiciousFile
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Trojan MLW
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Trojan Eldorado
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Trojan Downloader
GKWIKM.EXE 266aa1db1d62f940402a921a9883a9c6 Trojan Agent

GKWIKM.EXE size: 109568 bytes
GKWIKM.EXE hash: 266AA1DB1D62F940402A921A9883A9C6

Created files:

%SysDir%\gkwikm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Nationaldvj\Type: 10000000
HKLM\System\CurrentControlSet\Services\Nationaldvj\Start: 02000000
HKLM\System\CurrentControlSet\Services\Nationaldvj\DisplayName: Nationalmfk Instruments Domain Service
HKLM\System\CurrentControlSet\Services\Nationaldvj\ImagePath: %WinDir%\System32\gkwikm.exe
HKLM\System\CurrentControlSet\Services\Nationaldvj\Description: Providesvta a domain server for NI security.

Detected by UnHackMe:

GKWIKM.EXE
Default location: %SYSDIR%\GKWIKM.EXE

Dropper information:
MD5: 266aa1db1d62f940402a921a9883a9c6
File size: 109568 bytes

Leave a Reply