Solved! Use YBP.DLL (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

YBP.DLL – Backdoor Koutodoor removal

File MD5 Virus Alias
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Backdoor Koutodoor
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Trojan Generic
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Trojan Eldorado
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Trojan Adload
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Trojan Agent
YBP.DLL 8cf4c8f098ce3709205e385b02fb1c32 Trojan StartPage

YBP.DLL size: 53248 bytes
YBP.DLL hash: 8CF4C8F098CE3709205E385B02FB1C32

Created files:

%SysDir%\drivers\laj.sys
%SysDir%\ybp.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\laj\Type: 01000000
HKLM\System\CurrentControlSet\Services\laj\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\laj\DisplayName: laj
HKLM\System\CurrentControlSet\Services\laj\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C006C0061006A002E007300790073000000

Detected by UnHackMe:

YBP.DLL
Default location: %SYSDIR%\YBP.DLL

Dropper information:
MD5: 0c5e98b6473185695cdd51ac5c404ec0
File size: 122944 bytes

Leave a Reply