Solved! Use EMUIMO.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

EMUIMO.EXE – Backdoor Nitol removal

File MD5 Virus Alias
EMUIMO.EXE 6b0d95f49b7f88e06c434923f0f6687f Backdoor Nitol
EMUIMO.EXE 6b0d95f49b7f88e06c434923f0f6687f Trojan SuspiciousFile
EMUIMO.EXE 6b0d95f49b7f88e06c434923f0f6687f Trojan Agent
EMUIMO.EXE 6b0d95f49b7f88e06c434923f0f6687f Backdoor Zegost
EMUIMO.EXE 6b0d95f49b7f88e06c434923f0f6687f Backdoor Farfli

EMUIMO.EXE size: 19968 bytes
EMUIMO.EXE hash: 6B0D95F49B7F88E06C434923F0F6687F

Created files:

%WinDir%\emuimo.exe
%SysDir%\hra33.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Type: 10010000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Start: 02000000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\DisplayName: Stuvwx Abcdefgh Jklmnopq Stuv
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\ImagePath: %WinDir%\emuimo.exe
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Description: Stuvwxya Cdefghijk Mnopqrs Uvwxyabc Efg

Detected by UnHackMe:

EMUIMO.EXE
Default location: %WinDir%\EMUIMO.EXE

Dropper information:
MD5: 6b0d95f49b7f88e06c434923f0f6687f
File size: 19968 bytes

Leave a Reply