I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free Download Fully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
YKKGKK.EXE – Backdoor Nitol removal
| File | MD5 | Virus Alias |
|---|---|---|
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Backdoor Nitol |
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Trojan PAK_Generic |
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Trojan SuspiciousFile |
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Trojan Artemis |
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Trojan XPACK |
| YKKGKK.EXE | b8647ad3a57a5fea980dd8c44e92fc98 | Trojan CI |
YKKGKK.EXE size: 112128 bytes
YKKGKK.EXE hash: B8647AD3A57A5FEA980DD8C44E92FC98
Created files:
%SysDir%\gei33.dll
%SysDir%\ykkgkk.exe
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\aspnet_states\Type: 10000000
HKLM\System\CurrentControlSet\Services\aspnet_states\Start: 02000000
HKLM\System\CurrentControlSet\Services\aspnet_states\DisplayName: ASP.NET State Services
HKLM\System\CurrentControlSet\Services\aspnet_states\ImagePath: %WinDir%\System32\ykkgkk.exe
HKLM\System\CurrentControlSet\Services\aspnet_states\Description: Provides support for out-of-to-process
Detected by UnHackMe:
YKKGKK.EXE
Default location: %SYSDIR%\YKKGKK.EXE
Dropper information:
MD5: 80dca19a5138620c5fe5598979584d17
File size: 594944 bytes