Solved! Use ZUJFUS.EXE (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

ZUJFUS.EXE – Backdoor Nitol removal

File MD5 Virus Alias
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Backdoor Nitol
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Trojan SuspiciousFile
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Trojan Generic
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Backdoor RBot
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Trojan Buzus
ZUJFUS.EXE 12348e62ea69e1855aac6ded24de10a8 Backdoor Farfli

ZUJFUS.EXE size: 20992 bytes
ZUJFUS.EXE hash: 12348E62EA69E1855AAC6DED24DE10A8

Created files:

%SysDir%\hra33.dll
%WinDir%\zujfus.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\36\Type: 10010000
HKLM\System\CurrentControlSet\Services\36\Start: 02000000
HKLM\System\CurrentControlSet\Services\36\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\36\DisplayName: 36
HKLM\System\CurrentControlSet\Services\36\ImagePath: %WinDir%\zujfus.exe
HKLM\System\CurrentControlSet\Services\36\Description: 36

Detected by UnHackMe:

ZUJFUS.EXE
Default location: %WinDir%\ZUJFUS.EXE

Dropper information:
MD5: 12348e62ea69e1855aac6ded24de10a8
File size: 20992 bytes

Leave a Reply