USGMOI.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

USGMOI.EXE – Backdoor Nitol removal

FileMD5Virus Alias
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Backdoor Nitol
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Suspicious File
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Trojan Generic
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Trojan Downloader
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Trojan Agent
USGMOI.EXE d4a807f7691bd14ddf29858ef6a497d0 Trojan Small

USGMOI.EXE size: 40448 bytes
USGMOI.EXE hash: D4A807F7691BD14DDF29858EF6A497D0

Created files:

%SysDir%\usgmoi.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\National\Type: 10000000
HKLM\System\CurrentControlSet\Services\National\Start: 02000000
HKLM\System\CurrentControlSet\Services\National\DisplayName: Domain Service
HKLM\System\CurrentControlSet\Services\National\ImagePath: %WinDir%\System32\usgmoi.exe

Detected by UnHackMe:

USGMOI.EXE
Default location: %SYSDIR%\USGMOI.EXE

Dropper information:
MD5: c4d0087ebcdcaa94f2a5ef3a4ceb1dc3
File size: 48128 bytes

Leave a Reply