Trojan

Trojan:Win32/Koutodoor!pz removal tips

Malware Removal

The Trojan:Win32/Koutodoor!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Koutodoor!pz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:Win32/Koutodoor!pz?


File Info:

name: A1E847B960FF83286831.mlw
path: /opt/CAPEv2/storage/binaries/84b17ab9aa1506756028666f27ef1ff9b6d3d559cf9f04a7495315a1809cc701
crc32: B896ABB8
md5: a1e847b960ff832868310c7356bdca9e
sha1: 0c78327f624f17c1615764f26b52f383cbc89bb8
sha256: 84b17ab9aa1506756028666f27ef1ff9b6d3d559cf9f04a7495315a1809cc701
sha512: e3749049f12752a9abf2f3334c8a10eafdf0acf09739e265df52573ab0a155ee1f9ae5a2622c0e7b3e56bb0112927bc41aaa2cb2861c301cf1dd0ccf0b01dfa2
ssdeep: 3072:DB3MV+cFgH5oGVf4a7TSsoNfn1u4w/e+pgqur1CL2Gpfm1MJK6zFZcVnTsuZfl:xMV+SgHf4YOPu4w/oN1CLxfgFWsnwuZd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A54030D297DE076C5423132FC530E6C0620FCFCA79DFD82D6EAA70669EB1915A72A1D
sha3_384: 3473d875e92dc61652cb8b98b5bf2842eb9df1f208f3a1c3255211d64e5a1b11e4f9f7ade27f75f2599f8ddd0f82041d
ep_bytes: 558bec6aff6850a14000680c4b400064
timestamp: 2011-03-18 14:18:37

Version Info:

0: [No Data]

Trojan:Win32/Koutodoor!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Koutodoor.lmCq
MicroWorld-eScanGen:Variant.Koutodoor.18
FireEyeGeneric.mg.a1e847b960ff8328
SkyhighBehavesLike.Win32.Dropper.dh
McAfeeBackDoor-CEP.gen.cq
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Koutodoor.18
SangforSuspicious.Win32.Save.ins
K7AntiVirusBackdoor ( 004f992a1 )
AlibabaBackdoor:Win32/Koutodoor.8faa8ad6
K7GWBackdoor ( 004f992a1 )
BitDefenderThetaGen:NN.ZexaF.36804.rKX@amjWQ7jb
Paloaltogeneric.ml
SymantecTrojan.Koutodoor
ESET-NOD32a variant of Win32/Koutodoor.HM
APEXMalicious
TrendMicro-HouseCallTROJ_DLOADR.SMOM
AvastWin32:Caxnet [Trj]
ClamAVWin.Dropper.Agent-36201
KasperskyBackdoor.Win32.Koutodoor.aihc
BitDefenderGen:Variant.Koutodoor.18
NANO-AntivirusTrojan.Win32.RKDoor.evaszd
SUPERAntiSpywareBackdoor.Koutodoor/Variant
TencentTrojan.PSW.Win32.OnlineGame.d
EmsisoftGen:Variant.Koutodoor.18 (B)
F-SecureTrojan.TR/Koutodoor.psa
DrWebTrojan.Click1.41222
TrendMicroTROJ_DLOADR.SMOM
Trapminemalicious.high.ml.score
SophosMal/Koutodoor-A
IkarusGen.Variant.Renos
MAXmalware (ai score=100)
JiangminTrojan/Generic.dsff
WebrootW32.Backdoor.Koutodoor.Gen
GoogleDetected
AviraTR/Koutodoor.psa
VaristW32/Koutodoor.Y.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Koutodoor
KingsoftWin32.Troj.JunkcodeT.a.188672
MicrosoftTrojan:Win32/Koutodoor!pz
XcitiumTrojWare.Win32.Koutodoor.N@38d2va
ArcabitTrojan.Koutodoor.18
ViRobotBackdoor.Win32.Koutodoor.Gen.A
ZoneAlarmBackdoor.Win32.Koutodoor.aihc
GDataGen:Variant.Koutodoor.18
CynetMalicious (score: 100)
AhnLab-V3Dropper/Koutodoor2.Gen
Acronissuspicious
VBA32BScope.Trojan.Click
ALYacGen:Variant.Koutodoor.18
TACHYONBackdoor/W32.Koutodoor.282688.DO
Cylanceunsafe
PandaBck/Koutodoor.W
RisingTrojan.Win32.StartPage.qfr (CLASSIC)
YandexTrojan.GenAsa!/o4ApdjG9KY
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.Koutodoor.aihc
FortinetW32/Koutodoor.KWD!tr.bdr
AVGWin32:Caxnet [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Koutodoor.GU

How to remove Trojan:Win32/Koutodoor!pz?

Trojan:Win32/Koutodoor!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment