ookyou.exe – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

ookyou.exe – Backdoor Nitol removal

FileVirus Alias
ookyou.exe Backdoor Nitol
ookyou.exe Trojan Generic
ookyou.exe Trojan Downloader.Generic
ookyou.exe Trojan Agent
ookyou.exe Trojan Graftor
ookyou.exe Trojan Small

Created files:

%SysDir%\ookyou.exe – Backdoor Nitol

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribuntf\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribuntf\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribuntf\DisplayName: Distribugld Transaction Coordinator Service.
HKLM\System\CurrentControlSet\Services\Distribuntf\ImagePath: %WinDir%\System32\ookyou.exe

Detected by UnHackMe:

ookyou.exe
Default location: %SysDir%\ookyou.exe

Dropper information:
SHA256: 8db36de491f738f84381b0535618fa45bf8c9a64874edd12c7fe67c89ef13c2d
SHA1: c0480de21f7ba34f2e79a3f27068646db3c32400
MD5: 9d0f118e07d4659fb545e79ae46f8e29
File size: 33792 bytes

Leave a Reply