PCBRCM.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

PCBRCM.EXE – Backdoor Nitol removal

FileMD5Virus Alias
PCBRCM.EXE 0b81192ccab23f263073b9fbb58f2a89 Backdoor Nitol
PCBRCM.EXE 0b81192ccab23f263073b9fbb58f2a89 Trojan Downloader
PCBRCM.EXE 0b81192ccab23f263073b9fbb58f2a89 Trojan Agent
PCBRCM.EXE 0b81192ccab23f263073b9fbb58f2a89 Backdoor Farfli
PCBRCM.EXE 0b81192ccab23f263073b9fbb58f2a89 Trojan Scar

PCBRCM.EXE size: 56832 bytes

Created files:

%SysDir%\pcbrcm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DSLserverybs\Type: 10000000
HKLM\System\CurrentControlSet\Services\DSLserverybs\Start: 02000000
HKLM\System\CurrentControlSet\Services\DSLserverybs\DisplayName: DCOM Servermkg Process Launcher.
HKLM\System\CurrentControlSet\Services\DSLserverybs\ImagePath: %WinDir%\System32\pcbrcm.exe
HKLM\System\CurrentControlSet\Services\DSLserverybs\Description: DCOM Servercmc Process Launcher..

Detected by UnHackMe:

PCBRCM.EXE
Default location: %SYSDIR%\PCBRCM.EXE

Dropper information:
MD5: 0b81192ccab23f263073b9fbb58f2a89
File size: 56832 bytes

Leave a Reply