Solved! Use HRA33.DLL (Backdoor Nitol) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

HRA33.DLL – Backdoor Nitol removal

File MD5 Virus Alias
HRA33.DLL a3b02cfadd1ce8700a94aa08a83007b0 Backdoor Nitol
HRA33.DLL a3b02cfadd1ce8700a94aa08a83007b0 Trojan Graftor
HRA33.DLL a3b02cfadd1ce8700a94aa08a83007b0 Trojan Agent
HRA33.DLL a3b02cfadd1ce8700a94aa08a83007b0 Trojan Scar

HRA33.DLL size: 8704 bytes
HRA33.DLL hash: A3B02CFADD1CE8700A94AA08A83007B0

Created files:

%SysDir%\duzjuc.exe
%SysDir%\hra33.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Pqrstu Wxyabcde Ghi\Type: 10000000
HKLM\System\CurrentControlSet\Services\Pqrstu Wxyabcde Ghi\Start: 02000000
HKLM\System\CurrentControlSet\Services\Pqrstu Wxyabcde Ghi\DisplayName: Pqrstu Wxyabcde Ghijklmn Pqrs
HKLM\System\CurrentControlSet\Services\Pqrstu Wxyabcde Ghi\ImagePath: %WinDir%\System32\duzjuc.exe
HKLM\System\CurrentControlSet\Services\Pqrstu Wxyabcde Ghi\Description: Pqrstuvw Yabcdefgh Jklmnop Rstuvwxy Bcd

Detected by UnHackMe:

HRA33.DLL
Default location: %SYSDIR%\HRA33.DLL

Dropper information:
MD5: 40dc24a43f6184a6096407ebabe0b220
File size: 25088 bytes

Leave a Reply