Solved! Use LAJ.SYS (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LAJ.SYS – Backdoor Koutodoor removal

File MD5 Virus Alias
LAJ.SYS 1c44f353ae8bdc76efc434ce8c65967f Backdoor Koutodoor
LAJ.SYS 1c44f353ae8bdc76efc434ce8c65967f Trojan Generic
LAJ.SYS 1c44f353ae8bdc76efc434ce8c65967f Trojan Eldorado
LAJ.SYS 1c44f353ae8bdc76efc434ce8c65967f Trojan Agent
LAJ.SYS 1c44f353ae8bdc76efc434ce8c65967f Trojan Crypt

LAJ.SYS size: 38496 bytes
LAJ.SYS hash: 1C44F353AE8BDC76EFC434CE8C65967F

Created files:

%SysDir%\drivers\laj.sys
%SysDir%\ybp.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\laj\Type: 01000000
HKLM\System\CurrentControlSet\Services\laj\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\laj\DisplayName: laj
HKLM\System\CurrentControlSet\Services\laj\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C006C0061006A002E007300790073000000

Detected by UnHackMe:

LAJ.SYS
Default location: %SYSDIR%\DRIVERS\LAJ.SYS

Dropper information:
MD5: 0c5e98b6473185695cdd51ac5c404ec0
File size: 122944 bytes

Leave a Reply