Malware

DDoS:Win32/Nitol!pz removal

Malware Removal

The DDoS:Win32/Nitol!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoS:Win32/Nitol!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine DDoS:Win32/Nitol!pz?


File Info:

name: 1B4BB2DDF528BB8A4F6C.mlw
path: /opt/CAPEv2/storage/binaries/d9aa606eb1cebd0b520eaca8332327cd2ccb1164f87fe3835a6b7152a598bd60
crc32: 7894A33B
md5: 1b4bb2ddf528bb8a4f6c72721960cf56
sha1: 40f4553b9316822cc8db983960ff84630e0b238a
sha256: d9aa606eb1cebd0b520eaca8332327cd2ccb1164f87fe3835a6b7152a598bd60
sha512: b143770fa701f5ca2ff11d14aa5cd766b06bcefa378dd1c561c471de58d958bb83fe5354b0ff7ec22666b729f362a406b2b909379ac12b49327d64ca60589141
ssdeep: 768:4vQ5qDLHRdw2iPSMEk/6KMvumv1xuEMs96cyX1869IR555R:4vQoLHjw2iWPKMvHv1sMLyXuXR555R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159333A079F9CA49AD976123A2C957BFA696F6C3D460D9006FE41FA5E18F1C01EB3C503
sha3_384: a32b401a117ff323b0fd4df90c3468750cb312b25fd61226bb34360fb8be3b473d60902b50e0fbc751eaea90dea9540b
ep_bytes: 558bec6aff6870614000684039400064
timestamp: 2017-05-29 16:42:28

Version Info:

Comments:
CompanyName: Yagu Music
FileDescription: Clien RunProcess Local
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Yagu Music
PrivateBuild:
ProductName: Yagu Music® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Translation: 0x0409 0x04b0

DDoS:Win32/Nitol!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.Zard.30
ClamAVWin.Trojan.Nitol-6335025-0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.pm
McAfeeGenericRXHB-SG!1B4BB2DDF528
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Mint.Zard.30
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
K7GWTrojan ( 0054d1101 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Dnldr24.CYLH
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/ServStart.IK
ZonerTrojan.Win32.82643
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.GenKryptik.fnpygk
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
AvastWin32:Nitol-B [Trj]
TencentTrojan.Win32.Nitol.wa
EmsisoftGen:Heur.Mint.Zard.30 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader24.51669
TrendMicroDDOS_NITOL.SMF
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1b4bb2ddf528bb8a
SophosTroj/Nitol-BF
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.ServStart.F
JiangminTrojanDDoS.Nitol.cm
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitTrojan.Mint.Zard.30
ZoneAlarmVHO:Trojan-GameThief.Win32.Convagent.gen
MicrosoftDDoS:Win32/Nitol!pz
VaristW32/Heuristic-114!Eldorado
AhnLab-V3Trojan/Win.Nitol.R504648
Acronissuspicious
BitDefenderThetaAI:Packer.04A1A5D61F
MAXmalware (ai score=83)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallDDOS_NITOL.SMF
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
YandexTrojan.GenAsa!tlGQoZpZEz4
SentinelOneStatic AI – Malicious PE
MaxSecureDDoS.W32.Nitol.gen
FortinetMalwThreat!E1E6IV
AVGWin32:Nitol-B [Trj]
Cybereasonmalicious.b93168
DeepInstinctMALICIOUS

How to remove DDoS:Win32/Nitol!pz?

DDoS:Win32/Nitol!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment