Trojan

About “Trojan.DDoSNitol.P4” infection

Malware Removal

The Trojan.DDoSNitol.P4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DDoSNitol.P4 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

myss.ter.tf

How to determine Trojan.DDoSNitol.P4?


File Info:

crc32: 14577ECF
md5: 60a0a8e5bc5fbde278c8c74d6c5b0821
name: 60A0A8E5BC5FBDE278C8C74D6C5B0821.mlw
sha1: 58962ac3e6e1e72b6d42ab84c8da34742f283799
sha256: 4db5d99022504390342a9de01899a3051a0572b4cda9f9d640cd12d55fb780a2
sha512: 0b20531fe6f0469ab0abbe27e4d5d5d87be2cad55aa16a4d00204ccb62ed61e7b2b63ca3213cb351e02efd7169d9193a202ec92876cbb2914d073c09a57c643a
ssdeep: 384:QI0+Fkm7pWZvd3BMwt81FsgzEGYa9IgC/30QLw4VlEjjYg6IO5R3Wh9mW8m:QI0+FNpWL3Bm1nYiBC/30AXVkMg6I4W
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: ? Microsoft Corporation. All rights reserved.
InternalName:
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft? Windows? Operating System
SpecialBuild:
ProductVersion: 6.1.7600.16385
FileDescription: Windows Enhanced Storage Password Authentication Program
OriginalFilename: EhStorAuthn.exe
Translation: 0x0804 0x04b0

Trojan.DDoSNitol.P4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.16955
ClamAVWin.Malware.38aba-9860044-0
CAT-QuickHealTrojan.DDoSNitol.P4
McAfeeArtemis!60A0A8E5BC5F
CylanceUnsafe
ZillyaBackdoor.SdBot.Win32.16996
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/PornoBlocker.5cdf9c0d
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.5bc5fb
BaiduWin32.Trojan.ServStart.ax
CyrenW32/Nitol.AC.gen!Eldorado
SymantecBackdoor.Nitol
ESET-NOD32a variant of Win32/Agent.RMM
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.PornoBlocker.ejtx
BitDefenderTrojan.GenericKD.36899035
NANO-AntivirusTrojan.Win32.Agent.epcppg
SUPERAntiSpywareTrojan.Agent/Gen-FakeMS
MicroWorld-eScanTrojan.GenericKD.36899035
TencentTrojan.Win32.Lapka.bw
Ad-AwareTrojan.GenericKD.36899035
SophosMal/Generic-R + Mal/Behav-160
ComodoTrojWare.Win32.Nitol.KA@6cq5hu
BitDefenderThetaAI:Packer.F1AB88091F
VIPRETrojan.Win32.Generic!BT
TrendMicroDDoS.Win32.NITOL.SMG
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.60a0a8e5bc5fbde2
EmsisoftTrojan.GenericKD.36899035 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ovbd
WebrootW32.Trojan.Agent.Gen
AviraTR/ATRAPS.hrva.12
eGambitUnsafe.AI_Score_99%
MicrosoftDDoS:Win32/Nitol.P!bit
ArcabitTrojan.Generic.D23308DB
AegisLabTrojan.Win32.PornoBlocker.j!c
GDataWin32.Trojan.Microfake.A
TACHYONRansom/W32.PornoBlocker.47616
AhnLab-V3Trojan/Win32.Nitol.R299383
Acronissuspicious
VBA32BScope.Trojan.Scar
MAXmalware (ai score=81)
MalwarebytesMalware.AI.2833828501
PandaTrj/Genetic.gen
TrendMicro-HouseCallDDoS.Win32.NITOL.SMG
RisingRansom.PornoBlocker!8.24E (CLOUD)
YandexTrojan.GenAsa!H41PVEbKGsY
IkarusTrojan.Win32.MicroFake
FortinetW32/Agent.RMM!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Trojan.DDoSNitol.P4?

Trojan.DDoSNitol.P4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment