QWPUKG.SYS – Backdoor Koutodoor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

QWPUKG.SYS – Backdoor Koutodoor removal

File MD5 Virus Alias
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Backdoor Koutodoor
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Trojan SuspiciousFile
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Trojan Generic
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Trojan MLW
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Trojan Eldorado
QWPUKG.SYS 039da2337729431db0f2d2b17e17ca4c Trojan Agent

QWPUKG.SYS size: 41792 bytes
QWPUKG.SYS hash: 039DA2337729431DB0F2D2B17E17CA4C

Created files:

%SysDir%\bmor.dll
%SysDir%\drivers\qwpukg.sys
%TEMP%\ibijmg.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\qwpukg\Type: 01000000
HKLM\System\CurrentControlSet\Services\qwpukg\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\qwpukg\DisplayName: qwpukg
HKLM\System\CurrentControlSet\Services\qwpukg\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0071007700700075006B0067002E007300790073000000

Detected by UnHackMe:

QWPUKG.SYS
Default location: %SYSDIR%\DRIVERS\QWPUKG.SYS

Dropper information:
MD5: 2ff7d3292889296080c1a76fdd6f8976
File size: 249992 bytes

Leave a Reply