Malware

Troj/Nitol-AR removal instruction

Malware Removal

The Troj/Nitol-AR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Nitol-AR virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • A process attempted to delay the analysis task by a long amount of time.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

ilo.brenz.pl
zinoda.com
ant.trenz.pl
mfljwa.com
ftmypj.com
lpwwiu.com
tpfrfy.com
qhaixl.com
pudnze.com
jakaih.com
oxbthm.com
cmyvme.com
hkygpl.com
kozdim.com
dygzwa.com
lwoasu.com
oyaati.com
xzvmoj.com
elueax.com
bcoruq.com
aohgam.com
beekvu.com
ubglzo.com
eoybtc.com
glhxma.com
ihoeay.com
tegmhu.com
aqfqpq.com
bvqghi.com
ngaxaw.com
icuqyi.com
fyaujy.com
xclyuo.com
gydnxx.com
epeopi.com
ftgeqs.com
jsqxej.com
mruuyh.com
igyidt.com
nadula.com
arhwoi.com
yhuwto.com
afvshr.com
fxwmdc.com
aujkyx.com
nuoolo.com
uyexfs.com
hxohkr.com
hivlel.com
euchqu.com
crrycy.com
cfhvkd.com
ydaokl.com
vrayai.com
dpqbce.com
dtzdzi.com
ehetnj.com
fokhgj.com
btmsdi.com
bkwejo.com
pyqyiz.com
kfiugu.com
moiycf.com
cuibha.com
zowqmi.com
rcyalq.com
tzokkx.com
xybqlo.com
gfzizu.com
mjcxpy.com
loiznh.com
jskour.com
leiyiw.com
wlxpmi.com
lftopn.com
lhkazh.com
ukphpu.com
uaeaai.com
hzxain.com
jyfouu.com
laxrca.com
emautg.com
eeigee.com
nyfjxe.com
guayyf.com
gpoawd.com
einitm.com
zomedu.com
rbxofe.com
zeaihm.com
uhyeox.com
qtevfs.com
baalat.com
nsescr.com
nuyivi.com
ocaboc.com
alwwub.com
ueyxhu.com
uudple.com
kvidqu.com
vgndai.com
ewfvow.com

How to determine Troj/Nitol-AR?


File Info:

crc32: 5CC0E9CF
md5: c9c8d40656f16b4b50c9c08eb9a7aabc
name: Cd.exe
sha1: b40d0705f0aaf86ecca03165118c88299baf6ffb
sha256: 2aea443bcf9d86315722ce07d1f5a04bbb1afed14e54d9728da457fa2cdf5947
sha512: 39e121f18ce9d3624fbc55b2344fbab74b6d61aee0c982ec23968ab9f6e098a9ee5d3f78573a6f30559a2e5e25d1e217e073f3ace8eca262d335f6866d93b4a3
ssdeep: 12288:YRGPKEEgQBRtt/NXMTW9P1QpfXkHjA3bMi70yN9dLILecm6T6F:XKE9Gtt/hMTW9PWpfXz3bMi7bPdIKW2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Troj/Nitol-AR also known as:

BkavW32.Vetor.PE
MicroWorld-eScanWin32.Virtob.Gen.12
FireEyeGeneric.mg.c9c8d40656f16b4b
CylanceUnsafe
VIPREVirus.Win32.Virut.ce.5 (v)
SangforMalware
K7AntiVirusVirus ( f10002001 )
BitDefenderWin32.Virtob.Gen.12
K7GWVirus ( f10002001 )
Cybereasonmalicious.656f16
TrendMicroPE_VIRUX.O
BitDefenderThetaAI:FileInfector.C9457D4313
CyrenW32/Virut.E.gen!Eldorado
TotalDefenseWin32/Virut.17408
BaiduWin32.Virus.Virut.gen
APEXMalicious
AvastWin32:GenMalicious-BKJ [Trj]
ClamAVWin.Worm.Agent-5819819-0
GDataWin32.Virtob.Gen.12
KasperskyVirus.Win32.Virut.ce
AlibabaVirus:Win32/Virut.5508c62e
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C
AegisLabVirus.Win32.Virut.n!c
TencentVirus.Win32.Virut.Gen.200001
Ad-AwareWin32.Virtob.Gen.12
SophosTroj/Nitol-AR
ComodoVirus.Win32.Virut.CE@5jedjj
F-SecureTrojan:W97M/MaliciousMacro.GEN
DrWebWin32.Virut.56
ZillyaVirus.Virut.Win32.1938
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSGamania.cc
Trapminemalicious.high.ml.score
EmsisoftWin32.Virtob.Gen.12 (B)
IkarusTrojan-PWS.Win32.QQPass
F-ProtW32/Virut.E.gen!Eldorado
JiangminWin32/Virut.bt
MaxSecureVirus.Virut.CE
AviraW32/Virut.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Rootkit]/Win32.Lapka
KingsoftWin32.Virut.cr.61440
Endgamemalicious (high confidence)
ArcabitWin32.Virtob.Gen.12
ZoneAlarmVirus.Win32.Virut.ce
MicrosoftVirus:Win32/Virut.BO
AhnLab-V3Win32/Virut.F
Acronissuspicious
McAfeeW32/Virut.n.gen
TACHYONVirus/W32.Virut.Gen
VBA32Virus.Virut.14
MalwarebytesTrojan.Agent
PandaW32/Sality.AO
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallPE_VIRUX.O
RisingVirus.Virut!1.A08B (CLOUD)
YandexWin32.Virut.AB.Gen
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Virut.CE
AVGWin32:GenMalicious-BKJ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Virus.Win32.VirutChangeEntry.A

How to remove Troj/Nitol-AR?

Troj/Nitol-AR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment