Malware

DDoS:Win32/Nitol malicious file

Malware Removal

The DDoS:Win32/Nitol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoS:Win32/Nitol virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fwqyz.3322.org

How to determine DDoS:Win32/Nitol?


File Info:

crc32: 510042AB
md5: cb71fa0c0242b05451c335a8f3354f3c
name: CB71FA0C0242B05451C335A8F3354F3C.mlw
sha1: 0dc8cd8682a5382047c0d5bd44944a99e7f17209
sha256: 3831230b4e716422df687dc173c07ec51eb962cd6abca5123a54faff6ad40462
sha512: cf5c3e9b48733f46f0bacb3cc184d08978d82433bd8ba150fd3c156f584c64a6cbebc23ff6f72eccd48f65ebe284eb2e42a4d82f5bbc867c600e12963024084b
ssdeep: 768:GojY9PzAum/U12tZAW/BXc9jX/O8KDbZSAn6yHEojY9PoP+TIuoB:nmziI2tZ7XcYZVn6yH1mgP+K
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

DDoS:Win32/Nitol also known as:

BkavW32.MicroFakeDllA.Trojan
MicroWorld-eScanTrojan.Microfake.D
nProtectTrojan/W32.Microfake.57344
CMCTrojan.Win32.MicroFake!O
CAT-QuickHealTrojan.MicroFake.BA6
McAfeeTrojan-FCKC!CB71FA0C0242
MalwarebytesTrojan.MicroFake
ZillyaTrojan.Scar.Win32.37130
TheHackerTrojan/MicroFake.ba
BitDefenderTrojan.Microfake.D
K7GWTrojan ( 0040f89d1 )
K7AntiVirusTrojan ( 0040f89d1 )
TrendMicroWORM_NITOL.SMB0
BaiduWin32.Trojan.FakeMicro.c
CyrenW32/Risk.OEEL-3408
SymantecBackdoor.Trojan
TotalDefenseWin32/Redosdru.HF
TrendMicro-HouseCallWORM_NITOL.SMB0
AvastWin32:GenMalicious-EWM [Trj]
ClamAVWin.Trojan.Virut-19
KasperskyTrojan.Win32.MicroFake.ba
NANO-AntivirusTrojan.Win32.MicroFake.brqlq
ViRobotTrojan.Win32.Scar.45056.H[h]
AegisLabTroj.W32.MicroFake.lUSH
RisingBackdoor.Overie!1.64BD-3L8Of7yKp1 (cloud)
Ad-AwareTrojan.Microfake.D
SophosMal/Nitol-C
ComodoTrojWare.Win32.Ramnit.d
F-SecureTrojan:W32/MicroFake.A
DrWebDDoS.Rincux.623
VIPRETrojan.Win32.Ramnit.d (v)
Invinceaddos.win32.nitol.a
McAfee-GW-EditionBehavesLike.Win32.Virut.qh
EmsisoftTrojan.Microfake.D (B)
F-ProtW32/MalwareF.YMPW
JiangminTrojan/Generic.pai
AviraW32/Virut.H
FortinetW32/Dropper.RNS!tr
Antiy-AVLTrojan/Win32.MicroFake.ba
ArcabitTrojan.Microfake.D
SUPERAntiSpywareTrojan.Agent/Gen-Riskyr
MicrosoftDDoS:Win32/Nitol
AhnLab-V3Trojan/Win32.Scar.N2092532831
ALYacTrojan.Microfake.D
AVwareTrojan.Win32.Ramnit.d (v)
VBA32Trojan.MicroFake
ZonerTrojan.Agent.RNS
ESET-NOD32Win32/Agent.RNS
TencentWin32.Trojan.Fakeusp.Mgen
YandexTrojan.Scar!SvAe3OnybFg
IkarusTrojan.Backdoor.SuspectCRC
GDataTrojan.Microfake.D
AVGGeneric18.MDX
PandaTrj/Downloader.SKT
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360Trojan.Win32.FakeLPK.A

How to remove DDoS:Win32/Nitol?

DDoS:Win32/Nitol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment