Categories: Malware

DDoS:Win32/Nitol.G removal guide

The DDoS:Win32/Nitol.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoS:Win32/Nitol.G virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
892438912.f3322.net
258619738.f3322.net
www.hackxhzz.com

How to determine DDoS:Win32/Nitol.G?


File Info:

crc32: 23D237AEmd5: c27aee48cbdb885575b7711d0fc0a166name: svchost.exesha1: 0fe013934e3a2f20f70fefe5c68989cbdc9d37c0sha256: b0b39f6d3d2f051f3996a062a28fe14eaf781e8d0d99a779806c3d7e3485a45asha512: e03db2a9a7b7ce94c4632d7d1bf15eeab94cdc101f5f54a82349da5a2bb714b5487a3735e6b2d8879458332e45ce094a2754a2e839e2f4cdade168ae52924f9assdeep: 1536:+wPhg7Ot1W5jkTlAGu64sfLIyXOknfxKC32txchtwui/:lpgat1oYvMskYtfxjGt6ht1i/type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

DDoS:Win32/Nitol.G also known as:

Bkav W32.AIDetectVM.malware1
MicroWorld-eScan Gen:Variant.Mikey.15835
FireEye Generic.mg.c27aee48cbdb8855
CAT-QuickHeal DDoS.Nitol.S678880
McAfee RDN/Autorun.worm!do
ALYac Trojan.Agent.86016.G
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus Trojan ( 0053af701 )
BitDefender Gen:Variant.Mikey.15835
K7GW Trojan ( 0053af701 )
CrowdStrike win/malicious_confidence_100% (W)
TrendMicro WORM_NITOL.SMB0
Baidu Win32.Trojan.ServStart.ax
F-Prot W32/Busky.B.gen!Eldorado
Symantec Trojan.Gen
TotalDefense Win32/Nitol.APJRRXB
APEX Malicious
Avast Win32:Elknot-AA [Trj]
ClamAV Win.Trojan.Gh0stRAT-7480037-0
GData Gen:Variant.Mikey.15835
Kaspersky Trojan.Win32.Reconyc.dzpl
Alibaba DDoS:Win32/Reconyc.03225b84
NANO-Antivirus Trojan.Win32.Dwn.dpqsor
ViRobot Backdoor.Win32.S.Agent.86016.KV
AegisLab Trojan.Win32.Reconyc.mDci
Tencent Win32.Trojan.Reconyc.Swuk
Endgame malicious (high confidence)
Emsisoft Gen:Variant.Mikey.15835 (B)
Comodo TrojWare.Win32.Dialer.AFXP@4pjm0a
F-Secure Worm.WORM/Rbot.Gen
DrWeb Trojan.DownLoader12.48019
Zillya Trojan.Katusha.Win32.37532
Invincea heuristic
MaxSecure Trojan.Malware.8251757.susgen
Trapmine malicious.high.ml.score
Sophos Mal/Emogen-Y
Ikarus Trojan.Win32.Yoddos
Cyren W32/Busky.B.gen!Eldorado
Jiangmin Trojan/Generic.bcawe
Webroot W32.Worm.SMB0
Avira WORM/Rbot.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan/Win32.Reconyc.dzpl
Arcabit Trojan.Mikey.D3DDB
ZoneAlarm Trojan.Win32.Reconyc.dzpl
Microsoft DDoS:Win32/Nitol.G
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Nitol.R141988
VBA32 Trojan.Reconyc
TACHYON Trojan/W32.Reconyc.86016.D
Ad-Aware Gen:Variant.Mikey.15835
Panda Trj/Genetic.gen
ESET-NOD32 a variant of Win32/ServStart.P
TrendMicro-HouseCall WORM_NITOL.SMB0
Rising Backdoor.ServStart!1.AE0E (CLOUD)
Yandex Trojan.Agent!bOBc4heNNt4
SentinelOne DFI – Suspicious PE
eGambit Trojan.Generic
Fortinet W32/ServStart.P!worm
BitDefenderTheta Gen:NN.ZexaF.34132.fmW@aOHk57
AVG Win32:Elknot-AA [Trj]
Cybereason malicious.8cbdb8
Paloalto generic.ml
Qihoo-360 Win32/Trojan.232

How to remove DDoS:Win32/Nitol.G?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Jalapeno.2990”?

The Jalapeno.2990 is considered dangerous by lots of security experts. When this infection is active,…

11 seconds ago

Generic.Dacic.1370.2522AF06 removal

The Generic.Dacic.1370.2522AF06 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

About “Malware.AI.299088769” infection

The Malware.AI.299088769 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

About “Malware.AI.4098582889” infection

The Malware.AI.4098582889 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Backdoor:Win32/Subseven.2_1 information

The Backdoor:Win32/Subseven.2_1 is considered dangerous by lots of security experts. When this infection is active,…

31 mins ago

Marsilia.4611 removal tips

The Marsilia.4611 is considered dangerous by lots of security experts. When this infection is active,…

46 mins ago