VUZPQK.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

VUZPQK.EXE – Backdoor Nitol removal

FileMD5Virus Alias
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Backdoor Nitol
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Trojan SuspiciousFile
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Trojan XPACK
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Trojan Eldorado
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Trojan Agent
VUZPQK.EXE 8e2a9311e0694dfd9957e298f788393f Trojan Crypt

VUZPQK.EXE size: 104960 bytes
VUZPQK.EXE hash: 8E2A9311E0694DFD9957E298F788393F

Created files:

C:\26557df0.exe
%SysDir%\gei33.dll
%SysDir%\vuzpqk.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\aspnet_states\Type: 10000000
HKLM\System\CurrentControlSet\Services\aspnet_states\Start: 02000000
HKLM\System\CurrentControlSet\Services\aspnet_states\DisplayName: ASP.NET State Services
HKLM\System\CurrentControlSet\Services\aspnet_states\ImagePath: %WinDir%\System32\vuzpqk.exe
HKLM\System\CurrentControlSet\Services\aspnet_states\Description: Provides support for out-of-to-process

Detected by UnHackMe:

VUZPQK.EXE
Default location: %SYSDIR%\VUZPQK.EXE

Dropper information:
MD5: 8e2a9311e0694dfd9957e298f788393f
File size: 104960 bytes

Leave a Reply