RootKit.Win32.Fednu.w

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

RootKit.Win32.Fednu.w also known as W32/Koutodoor.A!tr.rkit, RTKT_KTDOOR.SMIB.

Malware Analysis of RootKit.Win32.Fednu.w – VIWE.SYS

Created files:

%Temp%\jatjoxn.bat
%Temp%\jqapbk.exe
%SysDir%\drivers\viwe.sys
%SysDir%\xscf.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\viw\ImagePath: “system32\drivers\viwe.sys”
HKLM\System\CurrentControlSet\Services\viw\DisplayName: “viw”

Detected by UnHackMe:

VIWE.SYS
Default location: %SYSDIR%\DRIVERS\VIWE.SYS

Dropper hash(md5): d851ec5f3870a751c6442f9561892c92

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera