JJXXIGWTUC.EXE – Backdoor Koutodoor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

JJXXIGWTUC.EXE – Backdoor Koutodoor removal

File MD5 Virus Alias
JJXXIGWTUC.EXE 0eafa239956f835acd714cf2b79555a2 Backdoor Koutodoor
JJXXIGWTUC.EXE 0eafa239956f835acd714cf2b79555a2 Trojan XPACK
JJXXIGWTUC.EXE 0eafa239956f835acd714cf2b79555a2 Trojan Crypt

JJXXIGWTUC.EXE size: 24576 bytes
JJXXIGWTUC.EXE hash: 0EAFA239956F835ACD714CF2B79555A2

Created files:

%SysDir%\drivers\bbjbdynqtw.sys
%SysDir%\jjxxigwtuc.dll
%SysDir%\jjxxigwtuc.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\bbjbdynqtw\Type: 01000000
HKLM\System\CurrentControlSet\Services\bbjbdynqtw\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\bbjbdynqtw\DisplayName: bbjbdynqtw
HKLM\System\CurrentControlSet\Services\bbjbdynqtw\ImagePath: %WinDir%\System32\drivers\bbjbdynqtw.sys
HKLM\System\CurrentControlSet\Services\bbjbdynqtw\Group: System Bus Extender

Detected by UnHackMe:

JJXXIGWTUC.EXE
Default location: %SYSDIR%\JJXXIGWTUC.EXE

Dropper information:
MD5: 061cf9c39e8906bd6a6abd699700a06c
File size: 23552 bytes

Leave a Reply