LRTJSDH.DLL – Backdoor Koutodoor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

LRTJSDH.DLL – Backdoor Koutodoor removal

FileMD5Virus Alias
LRTJSDH.DLL 26f1cf7e23c428e8c8befb737578fa99 Backdoor Koutodoor
LRTJSDH.DLL 26f1cf7e23c428e8c8befb737578fa99 Trojan Eldorado
LRTJSDH.DLL 26f1cf7e23c428e8c8befb737578fa99 Trojan Adload
LRTJSDH.DLL 26f1cf7e23c428e8c8befb737578fa99 Trojan Agent

LRTJSDH.DLL size: 53248 bytes
LRTJSDH.DLL hash: 26F1CF7E23C428E8C8BEFB737578FA99

Created files:

%SysDir%\drivers\fnedws.sys
%SysDir%\lrtjsdh.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\fnedws\Type: 01000000
HKLM\System\CurrentControlSet\Services\fnedws\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\fnedws\DisplayName: fnedws
HKLM\System\CurrentControlSet\Services\fnedws\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0066006E0065006400770073002E007300790073000000

Detected by UnHackMe:

LRTJSDH.DLL
Default location: %SYSDIR%\LRTJSDH.DLL

Dropper information:
MD5: 285d22d37ae584b4f4a7355b3275ca91
File size: 87808 bytes

Leave a Reply