Backdoor Koutodoor – ahmojx.bat – 0452a2dc6b26617b3a1ae7ada3433c3a

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Backdoor Koutodoor
Also known as: Trojan Generic, Trojan Small
SHA256: 51c8d6781483471da675343a495b3f7c29d907be9fe6fecee6e87795b948cebb
SHA1: 4f7c1893330f1d0bbcc8eaad98aba5b93cca0b3b
MD5: 0452a2dc6b26617b3a1ae7ada3433c3a
File size: 282688 bytes

Created files:

%SysDir%\ahmojx.bat – Backdoor Koutodoor
%SysDir%\drivers\bko.sys – Backdoor Koutodoor
%SysDir%\ghn.dll – Backdoor Koutodoor
%Temp%\lofbsxtq.bat – Backdoor Koutodoor
%Temp%\nasocvj.bat – Backdoor Koutodoor
%Temp%\onillx.exe – Backdoor Koutodoor
%Temp%\rcvuqe.bat – Backdoor Koutodoor
%Temp%\ybaczaw.bat – Backdoor Koutodoor
%Temp%\ytqeuo.exe – Backdoor Koutodoor

Backdoor Koutodoor created autostart registry keys:

HKLM\System\CurrentControlSet\Services\bko\Type: 01000000
HKLM\System\CurrentControlSet\Services\bko\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\bko\DisplayName: bko
HKLM\System\CurrentControlSet\Services\bko\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0062006B006F002E007300790073000000

Leave a Reply