Malware

Win32/Koutodoor.HL removal guide

Malware Removal

The Win32/Koutodoor.HL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Koutodoor.HL virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Win32/Koutodoor.HL?


File Info:

crc32: 882A2CA3
md5: 06ca0eb0a155afc4683ea62016724ece
name: 06CA0EB0A155AFC4683EA62016724ECE.mlw
sha1: fc75e49b373f15f8ca6f271683844f2494a91ccf
sha256: da2f6944b33faf0f3a0753398d3cebc66ed402b857efa3e35dbd6e42fd96948c
sha512: 24f152bf47f2e5b066d79ca83212ae1239332813eacaa2ca34dfaa606c076eb7aec7e9bc785cd9782140d53e91cf3bedeefedaada4c786dafdd117a1bab4fd88
ssdeep: 3072:ulzfI1Dz7OJz54uWtMYEGpgzXC1+baN2Bq:Wz0WFWLqLC1d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2010
ProductVersion: 1, 0, 0, 0
FileDescription:
FileVersion: 1, 0, 0, 0
CompanyName:
Translation: 0x0804 0x04b0

Win32/Koutodoor.HL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
VIPRETrojan.Win32.Koutodoor.e (v)
SangforRansom.Win32.Cerber_9.se
K7AntiVirusTrojan ( 001930d11 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 001930d11 )
Cybereasonmalicious.0a155a
BaiduWin32.Rootkit.Koutodoor.a
CyrenW32/Koutodoor.A.gen!Eldorado
SymantecTrojan.Koutodoor!gen
TotalDefenseWin32/Koutodoor.D!generic
APEXMalicious
AvastWin32:Koutodoor-E [Drp]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Koutodoor.ac54a9a2
NANO-AntivirusTrojan.Win32.MLW.evaszt
ViRobotBackdoor.Win32.Koutodoor.Gen.B
AegisLabTrojan.Win32.Generic.ljJU
RisingTrojan.Fedwj!1.98EA (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Zybr.B@1h4wl9
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen3.64149
ZillyaTrojan.Koutodoor.Win32.9507
TrendMicroBKDR_KTDOOR.SMIC
McAfee-GW-EditionBehavesLike.Win32.Koutodoor.cc
MaxSecureTrojan.Malware.2588.susgen
FireEyeGeneric.mg.06ca0eb0a155afc4
SophosML/PE-A + Mal/Koutodoor-A
IkarusTrojan.Win32.Koutodoor
GDataTrojan.Ransom.Cerber.1
JiangminTrojan/JunkCode.Gen
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Ransom.Cerber.1
SUPERAntiSpywareTrojan.Agent/Gen-Koutdoor
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Koutodoor.E
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Koutodoor12.Gen
Acronissuspicious
McAfeeKoutodoor.gen.g
VBA32BScope.Trojan.Click
MalwarebytesMachineLearning/Anomalous.100%
PandaBck/Koutodoor.E
ESET-NOD32a variant of Win32/Koutodoor.HL
TrendMicro-HouseCallBKDR_KTDOOR.SMIC
TencentTrojan.Win32.WNDABC.a
YandexTrojan.GenAsa!KQrFYbXCY+U
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Koutodoor.D!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34590.iu1@aOV!3Rab
AVGWin32:Koutodoor-E [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Trojan.Win32.Koutodoor.AS

How to remove Win32/Koutodoor.HL?

Win32/Koutodoor.HL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment