Malware

Troj/Nitol-BH malicious file

Malware Removal

The Troj/Nitol-BH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Nitol-BH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Nitol-BH?


File Info:

name: C1B7D240B80078465109.mlw
path: /opt/CAPEv2/storage/binaries/056e9e4bf9cec0b1b5e36c1999da892cafba68adf5f4e05a65a0090cb2ee1cc0
crc32: DD6A3EBA
md5: c1b7d240b800784651098822926841d6
sha1: 97c14b70c7dba96aa9b78abb5c812258fcc32730
sha256: 056e9e4bf9cec0b1b5e36c1999da892cafba68adf5f4e05a65a0090cb2ee1cc0
sha512: 3f8d9879a1f2354fff6f9627cdbae1743e934905d27e886cf9e7634045961029119f856d747d7653482105452506d3a921ecc3563cf6c6532ccfb7fbeba36b77
ssdeep: 768:TymYzyN7c9SKiGsU8fKKZuJvSvlGyHg95fpp0NwIifu:8GN7c9SKiGN8fz1lGyHm54qJfu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E238D47ED8558F3F12700BC245EA3BA4ABB8C36476EA187DF81CCD218F2534EA75189
sha3_384: bcb4783959996828f158b547f5ef72eb5a6a02e292014e09f217ca0de796909da17afe6051d455a660bbe6fac90af41f
ep_bytes: 558bec6aff6848664000687058400064
timestamp: 2055-05-25 18:10:40

Version Info:

0: [No Data]

Troj/Nitol-BH also known as:

BkavW32.Vetor.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Virtob.3.Gen
CAT-QuickHealW32.Virut.D
SkyhighBehavesLike.Win32.PWSZbot.ph
McAfeeW32/Virut.j.gen
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00526ea91 )
K7GWTrojan ( 00526ea91 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Virtob.3.Gen
BaiduWin32.Virus.Virut.i
VirITWin32.Cheburgen.A
SymantecW32.Virut.U
tehtrisGeneric.Malware
ESET-NOD32Win32/Virut.O
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Virut-41
KasperskyVirus.Win32.Virut.q
BitDefenderWin32.Virtob.3.Gen
NANO-AntivirusTrojan.Win32.ServStart.jpedku
SUPERAntiSpywareTrojan.Agent/Gen-DDOS
AvastWin32:BotX-gen [Trj]
TencentTrojan.Win32.FakeLpk.bkd
EmsisoftWin32.Virtob.3.Gen (B)
F-SecureMalware.W32/Virut.U
DrWebWin32.Virut.5
VIPREWin32.Virtob.3.Gen
TrendMicroTROJ_VSTART.SMA
SophosTroj/Nitol-BH
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.f
WebrootTrojan:Win32/ServStart.A
VaristW32/QQhelper.C.gen!Eldorado
AviraW32/Virut.U
MAXmalware (ai score=86)
Antiy-AVLVirus/Win32.Virut.n
KingsoftWin32.Virut.ce.57344
XcitiumVirus.Win32.Virut.q@1fhkey
MicrosoftVirus:Win32/Virut.AE
ViRobotWin32.Virut.Gen.B
ZoneAlarmVirus.Win32.Virut.q
GDataWin32.Trojan.Nitol.C
GoogleDetected
AhnLab-V3Win32/Virut.C
Acronissuspicious
BitDefenderThetaAI:FileInfector.D6DFFBB612
VBA32Virus.Virut.07
Cylanceunsafe
PandaW32/Virutas.gen
ZonerTrojan.Win32.19793
TrendMicro-HouseCallTROJ_VSTART.SMA
RisingVirus.Virut!1.A08C (CLASSIC)
YandexTrojan.GenAsa!m4lop/Fma4M
IkarusTrojan.Win32.ServStart
MaxSecureVirus.Virut.Gen
FortinetW32/MicroFake.A!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.0c7dba
DeepInstinctMALICIOUS

How to remove Troj/Nitol-BH?

Troj/Nitol-BH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment