Backdoor Koutodoor – vdl.sys – 00ac4d9a9e61d1fa561c4d08cd732f6d

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Backdoor Koutodoor
Also known as: Trojan Renos, Trojan Eldorado
SHA256: 7e53402524f2771e2244baacb8f95517c301a52d94684d38e4a77bb581057a03
SHA1: ba8331050119f3c127cee07ec0493e113ea9ed75
MD5: 00ac4d9a9e61d1fa561c4d08cd732f6d
File size: 286784 bytes

Created files:

%SysDir%\drivers\vdl.sys – Backdoor Koutodoor
%SysDir%\qivjfc.bat – Backdoor Koutodoor
%SysDir%\zly.dll – Backdoor Koutodoor
%Temp%\qozjqrz.bat – Backdoor Koutodoor
%Temp%\qrjpea.exe – Backdoor Koutodoor
%Temp%\wupwaiar.bat – Backdoor Koutodoor

Backdoor Koutodoor created autostart registry keys:

HKLM\System\CurrentControlSet\Services\vdl\Type: 01000000
HKLM\System\CurrentControlSet\Services\vdl\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\vdl\DisplayName: vdl
HKLM\System\CurrentControlSet\Services\vdl\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C00760064006C002E007300790073000000

Leave a Reply