Solved! Use UGMYCM.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UGMYCM.EXE – Backdoor Nitol removal

FileMD5Virus Alias
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Backdoor Nitol
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Trojan Eldorado
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Adware Downware
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Backdoor RBot
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Trojan Downloader
UGMYCM.EXE b328254de9d7bca46837f1676f6457b4 Trojan Agent

UGMYCM.EXE size: 41472 bytes
UGMYCM.EXE hash: B328254DE9D7BCA46837F1676F6457B4

Created files:

%SysDir%\ugmycm.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Distribuufe\Type: 10000000
HKLM\System\CurrentControlSet\Services\Distribuufe\Start: 02000000
HKLM\System\CurrentControlSet\Services\Distribuufe\DisplayName: Distribubbg Transaction Coordinator Service
HKLM\System\CurrentControlSet\Services\Distribuufe\ImagePath: %WinDir%\System32\ugmycm.exe

Detected by UnHackMe:

UGMYCM.EXE
Default location: %SYSDIR%\UGMYCM.EXE

Dropper information:
MD5: b328254de9d7bca46837f1676f6457b4
File size: 41472 bytes

Leave a Reply