Solved! Use NARPAU.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NARPAU.EXE – Backdoor Nitol removal

File MD5 Virus Alias
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Backdoor Nitol
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Trojan SuspiciousFile
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Trojan XPACK
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Trojan Generic
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Worm MyDoom
NARPAU.EXE 274498581bcac1f02adf94a49d226ec8 Trojan Agent

NARPAU.EXE size: 18432 bytes
NARPAU.EXE hash: 274498581BCAC1F02ADF94A49D226EC8

Created files:

%WinDir%\narpau.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Type: 10010000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Start: 02000000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\DisplayName: Stuvwx Abcdefgh Jklmnopq Stuv
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\ImagePath: %WinDir%\narpau.exe
HKLM\System\CurrentControlSet\Services\Stuvwx Abcdefgh Jkl\Description: Stuvwxya Cdefghijk Mnopqrs Uvwxyabc Efg

Detected by UnHackMe:

NARPAU.EXE
Default location: %WinDir%\NARPAU.EXE

Dropper information:
MD5: 274498581bcac1f02adf94a49d226ec8
File size: 18432 bytes

Leave a Reply