Backdoor Koutodoor – ehnhkp.sys – 006150a92deea7726aec779a312e5568

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Backdoor Koutodoor
Also known as: Trojan Agent, Trojan Banker
SHA256: 05a9dfa50ca225dccf6d29046eef0038a646d24e17e1bc66c0d659151d4bf236
SHA1: 11d6e688d68347a81ed593258603f7367359b74e
MD5: 006150a92deea7726aec779a312e5568
File size: 131328 bytes

Created files:

%SysDir%\drivers\ehnhkp.sys – Backdoor Koutodoor
%SysDir%\hwzkmt.bat – Backdoor Koutodoor
%SysDir%\vbx.dll – Backdoor Koutodoor

Backdoor Koutodoor created autostart registry keys:

HKLM\System\CurrentControlSet\Services\ehnhkp\Type: 01000000
HKLM\System\CurrentControlSet\Services\ehnhkp\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ehnhkp\DisplayName: ehnhkp
HKLM\System\CurrentControlSet\Services\ehnhkp\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C00650068006E0068006B0070002E007300790073000000

Leave a Reply