Solved! Use NIJLIK.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NIJLIK.EXE – Backdoor Nitol removal

File MD5 Virus Alias
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Backdoor Nitol
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Trojan SuspiciousFile
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Trojan Artemis
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Trojan Generic
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Backdoor RBot
NIJLIK.EXE d1670fec84f59ea9fe339594994c8c77 Trojan Agent

NIJLIK.EXE size: 20480 bytes
NIJLIK.EXE hash: D1670FEC84F59EA9FE339594994C8C77

Created files:

%WinDir%\nijlik.exe
%SysDir%\hra33.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\TCP Mnager Service\Type: 10010000
HKLM\System\CurrentControlSet\Services\TCP Mnager Service\Start: 02000000
HKLM\System\CurrentControlSet\Services\TCP Mnager Service\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\TCP Mnager Service\DisplayName: TCP Mnager Service
HKLM\System\CurrentControlSet\Services\TCP Mnager Service\ImagePath: %WinDir%\nijlik.exe
HKLM\System\CurrentControlSet\Services\TCP Mnager Service\Description: TCP Mnager Service

Detected by UnHackMe:

NIJLIK.EXE
Default location: %WinDir%\NIJLIK.EXE

Dropper information:
MD5: d1670fec84f59ea9fe339594994c8c77
File size: 20480 bytes

Leave a Reply