Solved! Use TKXLKI.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

TKXLKI.EXE – Backdoor Nitol removal

File MD5 Virus Alias
TKXLKI.EXE 7d3ab083d206ce54f60eafff5e3fce8b Backdoor Nitol
TKXLKI.EXE 7d3ab083d206ce54f60eafff5e3fce8b Trojan SuspiciousFile
TKXLKI.EXE 7d3ab083d206ce54f60eafff5e3fce8b Trojan Artemis
TKXLKI.EXE 7d3ab083d206ce54f60eafff5e3fce8b Trojan Agent
TKXLKI.EXE 7d3ab083d206ce54f60eafff5e3fce8b Backdoor Zegost

TKXLKI.EXE size: 19968 bytes
TKXLKI.EXE hash: 7D3AB083D206CE54F60EAFFF5E3FCE8B

Created files:

%SysDir%\hra33.dll
%WinDir%\tkxlki.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Type: 10010000
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Start: 02000000
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\DisplayName: Vwxyab Defghijk Mnopqrst Vwxy
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\ImagePath: %WinDir%\tkxlki.exe
HKLM\System\CurrentControlSet\Services\Vwxyab Defghijk Mno\Description: Vwxyabcd Fghijklmn Pqrstuv Xyabcdef Hij

Detected by UnHackMe:

TKXLKI.EXE
Default location: %WinDir%\TKXLKI.EXE

Dropper information:
MD5: 7d3ab083d206ce54f60eafff5e3fce8b
File size: 19968 bytes

Leave a Reply