Solved! Use XOHDOK.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

XOHDOK.EXE – Backdoor Nitol removal

File MD5 Virus Alias
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Backdoor Nitol
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Trojan SuspiciousFile
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Trojan Generic
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Trojan Eldorado
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Trojan Downloader
XOHDOK.EXE 1c41cdd417ff5fbfd04520de93444668 Trojan Agent

XOHDOK.EXE size: 56832 bytes
XOHDOK.EXE hash: 1C41CDD417FF5FBFD04520DE93444668

Created files:

%SysDir%\xohdok.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DSLserverorm\Type: 10000000
HKLM\System\CurrentControlSet\Services\DSLserverorm\Start: 02000000
HKLM\System\CurrentControlSet\Services\DSLserverorm\DisplayName: DCOM Serverxlp Process Launcher.
HKLM\System\CurrentControlSet\Services\DSLserverorm\ImagePath: %WinDir%\System32\xohdok.exe
HKLM\System\CurrentControlSet\Services\DSLserverorm\Description: DCOM Servernia Process Launcher..

Detected by UnHackMe:

XOHDOK.EXE
Default location: %SYSDIR%\XOHDOK.EXE

Dropper information:
MD5: 1c41cdd417ff5fbfd04520de93444668
File size: 56832 bytes

Leave a Reply