Backdoor Koutodoor – yhjpv.sys – 0175a8488a901f50c70c2df572e85fa2

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

Backdoor Koutodoor
Also known as: Trojan Eldorado, Trojan Agent
SHA256: c55571b95a94517b85be9c1e6c76b4a022e8f3a8c8a1b2ebb5424f44c65f3bfd
SHA1: 6228b65e9f7200aba1fad54c472ba135108a9acc
MD5: 0175a8488a901f50c70c2df572e85fa2
File size: 155904 bytes

Created files:

%SysDir%\drivers\yhjpv.sys – Backdoor Koutodoor
%SysDir%\lkxmsk.bat – Backdoor Koutodoor
%SysDir%\qhw.dll – Backdoor Koutodoor

Backdoor Koutodoor created autostart registry keys:

HKLM\System\CurrentControlSet\Services\yhjpv\Type: 01000000
HKLM\System\CurrentControlSet\Services\yhjpv\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\yhjpv\DisplayName: yhjpv
HKLM\System\CurrentControlSet\Services\yhjpv\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C00790068006A00700076002E007300790073000000

Leave a Reply