Home Malware Programs Backdoors Backdoor.Nitol

Backdoor.Nitol

Posted: April 25, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 65
First Seen: April 25, 2012
OS(es) Affected: Windows

Backdoor.Nitol is a Windows backdoor Trojan. The file (6 arbitrary symbols, not counting the .exe extension) of Backdoor.Nitol is
installed onto the compromised machine as an executable in a Program Files folder. Backdoor.Nitol controls processes on the
infected computer system looking for the two of them named Rfwsrv.exe and RavMonD.exe. Backdoor.Nitol creates its own process where it finds them, that deletes one of them if only one has been found or both processes. Backdoor.Nitol is guided to gather essential information on targeted computer, namely its type of operating system, location and other. The gathered information is then transmitted to one of the servers controlled by attackers. Backdoor.Nitol can also download and install additional malware threats on your computer. Select a reputable security program for removal of Backdoor.Nitol.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\[SIX RANDOM CHARACTERS].exe File name: %ProgramFiles%\[SIX RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%stf[FIVE RANDOM CHARACTERS].exe File name: %Temp%stf[FIVE RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...