TORZOA.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TORZOA.EXE – Backdoor Nitol removal

FileMD5Virus Alias
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Backdoor Nitol
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Trojan SuspiciousFile
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Trojan Artemis
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Trojan Generic
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Trojan Downloader
TORZOA.EXE 2669f6a18e47c15d5273ebd0c3dfa164 Trojan Agent

TORZOA.EXE size: 39936 bytes
TORZOA.EXE hash: 2669F6A18E47C15D5273EBD0C3DFA164

Created files:

%SysDir%\torzoa.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribukfo\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribukfo\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribukfo\DisplayName: Distribuivr Transaction Coordinator Service
HKLM\System\CurrentControlSet\Services\Distribukfo\ImagePath: %WinDir%\System32\torzoa.exe

Detected by UnHackMe:

TORZOA.EXE
Default location: %SYSDIR%\TORZOA.EXE

Dropper information:
MD5: b892a7a3cdff95a4fbdfe62aa2139044
File size: 47616 bytes

Leave a Reply