Malware

About “DDoSTool.Nitol.UPX” infection

Malware Removal

The DDoSTool.Nitol.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoSTool.Nitol.UPX virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine DDoSTool.Nitol.UPX?


File Info:

crc32: 5286D060
md5: 0c8650578b5cbc06c7d1bd24eef9dc20
name: cc.exe
sha1: c4e21a614e50528018db8dcb81ad04113465c6c5
sha256: 637e7368e74a0bbfe7a7fb78e1a389a28b0e320fd30dde908620785f23e8c415
sha512: 68a0c2672cddd2ce59a777e64bd2ba5274a7f99c79c999e4d10e626569c785d1e21cb2bc42a8f97eb1812e4ec56b108b8cb4431fd581bb57bd1cb3514493a22a
ssdeep: 192:1Bk2UvX8HFgpVA51APmRJ4V41f8/ku4GNb:1q2UUkA51Rh1OkuRNb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

DDoSTool.Nitol.UPX also known as:

MicroWorld-eScanGeneric.ServStart.B.E177A524
FireEyeGeneric.mg.0c8650578b5cbc06
McAfeeArtemis!0C8650578B5C
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
AegisLabTrojan.Win32.Agent.l8cj
SangforMalware
K7AntiVirusTrojan ( 004bdcaa1 )
BitDefenderGeneric.ServStart.B.E177A524
K7GWTrojan ( 004bdcaa1 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/Downloader.AL.gen!Eldorado
TotalDefenseWin32/PackedBaidu
APEXMalicious
AvastWin32:Dh-A [Heur]
GDataGeneric.ServStart.B.E177A524
KasperskyHEUR:Trojan.Win32.Generic
AlibabaDDoS:Win32/Nitol.2129de93
NANO-AntivirusTrojan.Win32.Rbot.fkropl
TencentWin32.Worm.Rbot.Hpe
Endgamemalicious (moderate confidence)
SophosMal/Behav-004
ComodoTrojWare.Win32.Nitol.DE@816zhh
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.DownLoader27.17979
TrendMicroTROJ_GEN.R002C0DC520
McAfee-GW-EditionBehavesLike.Win32.Sality.xc
Trapminemalicious.high.ml.score
EmsisoftGeneric.ServStart.B.E177A524 (B)
IkarusTrojan.Win32.Dialer
CyrenW32/Downloader.AL.gen!Eldorado
JiangminTrojan.Generic.cuvxk
WebrootW32.Trojan.Gen
AviraWORM/Rbot.Gen
eGambitTrojan.Generic
Antiy-AVLTrojan/Win32.Nitol
MicrosoftDDoS:Win32/Nitol.B
ArcabitGeneric.ServStart.B.E177A524
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.SCKeyLog.C82208
Acronissuspicious
VBA32BScope.Trojan.SvcHorse.01643
ALYacGeneric.ServStart.B.E177A524
MAXmalware (ai score=100)
Ad-AwareGeneric.ServStart.B.E177A524
MalwarebytesDDoSTool.Nitol.UPX
PandaTrj/CI.A
ESET-NOD32a variant of Win32/ServStart.DE
TrendMicro-HouseCallTROJ_GEN.R002C0DC520
RisingTrojan.ServStart!8.107 (TFE:5:tDaOjeT836T)
YandexTrojan.Agent!NAFpdmZf09U
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Nitol.B!tr
BitDefenderThetaAI:Packer.F377EF311E
AVGFileRepMalware
Cybereasonmalicious.78b5cb
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.e04

How to remove DDoSTool.Nitol.UPX?

DDoSTool.Nitol.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment