Solved! Use UFVR.DLL (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

UFVR.DLL – Backdoor Koutodoor removal

FileMD5Virus Alias
UFVR.DLL 00009cadc624dd7e5f148bf5daa2cb20 Backdoor Koutodoor
UFVR.DLL 00009cadc624dd7e5f148bf5daa2cb20 Trojan Generic
UFVR.DLL 00009cadc624dd7e5f148bf5daa2cb20 Trojan Eldorado
UFVR.DLL 00009cadc624dd7e5f148bf5daa2cb20 Trojan Adload
UFVR.DLL 00009cadc624dd7e5f148bf5daa2cb20 Trojan Agent

UFVR.DLL size: 53248 bytes
UFVR.DLL hash: 00009CADC624DD7E5F148BF5DAA2CB20

Created files:

%SysDir%\drivers\rncemrz.sys
%SysDir%\ufvr.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\rncemrz\Type: 01000000
HKLM\System\CurrentControlSet\Services\rncemrz\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\rncemrz\DisplayName: rncemrz
HKLM\System\CurrentControlSet\Services\rncemrz\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0072006E00630065006D0072007A002E007300790073000000

Detected by UnHackMe:

UFVR.DLL
Default location: %SYSDIR%\UFVR.DLL

Dropper information:
MD5: 4211148da107f8799fc4a87d9bf3d7e5
File size: 122944 bytes

Leave a Reply