Malware

DDoS:Win32/Nitol!rfn removal guide

Malware Removal

The DDoS:Win32/Nitol!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoS:Win32/Nitol!rfn virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

seojin6125.codns.com

How to determine DDoS:Win32/Nitol!rfn?


File Info:

crc32: 38AFF3ED
md5: 122cc399bf6fe7dc6b9c2d8cd846631b
name: 122CC399BF6FE7DC6B9C2D8CD846631B.mlw
sha1: 505a2bed4eba85b9fc9cb02e3b55046c59b67403
sha256: 5b50cb94c6e4dbd73a67f1f5c99c3ff3d7b883915caa5769b470d01a869bd31a
sha512: 848fe1f9733f229c9ca7e93fdaa2b342dda9c28e8226dab8c0d5fde6816253d897269a8a098ec52d488b3aecfeff722550147efdc47dd5c63faf58062035c7cf
ssdeep: 12288:ni7vDj1tVmBPvqUU5wrvriJxlMFXw34GcVvSpWErfgAas2XWmRH3atculwT0OvNd:nGD5tABHqUkwrjWH3XcsMETYpa92TVFd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

DDoS:Win32/Nitol!rfn also known as:

MicroWorld-eScanTrojan.Generic.21123108
FireEyeGeneric.mg.122cc399bf6fe7dc
Qihoo-360Win32/Trojan.491
McAfeeGeneric.axp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004cfcad1 )
BitDefenderTrojan.Generic.21123108
K7GWTrojan ( 004cfcad1 )
Cybereasonmalicious.9bf6fe
CyrenW32/Zusy.FB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Ranky.53760.B
RisingBackdoor.Overie!1.64BD (CLASSIC)
Ad-AwareTrojan.Generic.21123108
EmsisoftTrojan.Generic.21123108 (B)
ComodoTrojWare.Win32.Medbot.dc@4rleim
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.DownLoader10.22140
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
SophosTroj/Agent-APDC
JiangminTrojan/Horst.c
AviraWORM/Rbot.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftDDoS:Win32/Nitol!rfn
ArcabitTrojan.Generic.D1425024
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan-DDoS.Win32.Nitol.gen
GDataTrojan.Generic.21123108
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C1808518
BitDefenderThetaGen:NN.ZexaF.34804.7u1@au5Tb0kb
ALYacTrojan.Generic.21123108
MAXmalware (ai score=86)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.DXOY
TencentWin32.Worm.Rbot.Dumm
YandexPacked/CExe
IkarusPUA.NoobyProtect
AVGWin32:ServStart-B [Trj]
AvastWin32:ServStart-B [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove DDoS:Win32/Nitol!rfn?

DDoS:Win32/Nitol!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment