Solved! Use WDP.SYS (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

WDP.SYS – Backdoor Koutodoor removal

File MD5 Virus Alias
WDP.SYS 4a85184c21699025d84f2bd86af23406 Backdoor Koutodoor
WDP.SYS 4a85184c21699025d84f2bd86af23406 Trojan Generic
WDP.SYS 4a85184c21699025d84f2bd86af23406 Trojan MLW
WDP.SYS 4a85184c21699025d84f2bd86af23406 Trojan Eldorado
WDP.SYS 4a85184c21699025d84f2bd86af23406 Trojan Agent
WDP.SYS 4a85184c21699025d84f2bd86af23406 Trojan Crypt

WDP.SYS size: 41024 bytes
WDP.SYS hash: 4A85184C21699025D84F2BD86AF23406

Created files:

%SysDir%\drivers\wdp.sys
%SysDir%\xduqvl.dll
%Temp%\enzzrn.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\wdp\Type: 01000000
HKLM\System\CurrentControlSet\Services\wdp\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\wdp\DisplayName: wdp
HKLM\System\CurrentControlSet\Services\wdp\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C007700640070002E007300790073000000

Detected by UnHackMe:

WDP.SYS
Default location: %SYSDIR%\DRIVERS\WDP.SYS

Dropper information:
MD5: 60818dd62190354c0cf9581e15ad1a0d
File size: 200768 bytes

Leave a Reply