XFL.SYS – Backdoor Koutodoor

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

XFL.SYS – Backdoor Koutodoor removal

File MD5 Virus Alias
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Backdoor Koutodoor
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Trojan SuspiciousFile
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Trojan Generic
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Trojan MLW
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Trojan Eldorado
XFL.SYS 3cc1c3733ffb78abf8d8349eaa69b02b Trojan Agent

XFL.SYS size: 42112 bytes
XFL.SYS hash: 3CC1C3733FFB78ABF8D8349EAA69B02B

Created files:

%SysDir%\drivers\xfl.sys
%SysDir%\kazwitk.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\xfl\Type: 01000000
HKLM\System\CurrentControlSet\Services\xfl\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\xfl\DisplayName: xfl
HKLM\System\CurrentControlSet\Services\xfl\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C00780066006C002E007300790073000000

Detected by UnHackMe:

XFL.SYS
Default location: %SYSDIR%\DRIVERS\XFL.SYS

Dropper information:
MD5: 040d5b723da32242df6ff9a2603ae71a
File size: 151536 bytes

Leave a Reply