Solved! Use XDUQVL.DLL (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

XDUQVL.DLL – Backdoor Koutodoor removal

File MD5 Virus Alias
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Backdoor Koutodoor
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Trojan Generic
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Trojan Eldorado
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Trojan Adload
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Trojan Agent
XDUQVL.DLL 2986fc6d542462492e27948fd494fcd0 Trojan StartPage

XDUQVL.DLL size: 65536 bytes
XDUQVL.DLL hash: 2986FC6D542462492E27948FD494FCD0

Created files:

%SysDir%\drivers\wdp.sys
%SysDir%\xduqvl.dll
%Temp%\enzzrn.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\wdp\Type: 01000000
HKLM\System\CurrentControlSet\Services\wdp\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\wdp\DisplayName: wdp
HKLM\System\CurrentControlSet\Services\wdp\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C007700640070002E007300790073000000

Detected by UnHackMe:

XDUQVL.DLL
Default location: %SYSDIR%\XDUQVL.DLL

Dropper information:
MD5: 60818dd62190354c0cf9581e15ad1a0d
File size: 200768 bytes

Leave a Reply