Solved! Use SLJ.SYS (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SLJ.SYS – Backdoor Koutodoor removal

File MD5 Virus Alias
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Backdoor Koutodoor
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Trojan Generic
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Trojan MLW
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Trojan Eldorado
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Trojan Renos
SLJ.SYS ff8b5c5c77ae94f7a22338221aa1a481 Trojan Agent

SLJ.SYS size: 41408 bytes
SLJ.SYS hash: FF8B5C5C77AE94F7A22338221AA1A481

Created files:

%SysDir%\deksb.dll
%SysDir%\drivers\slj.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\slj\Type: 01000000
HKLM\System\CurrentControlSet\Services\slj\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\slj\DisplayName: slj
HKLM\System\CurrentControlSet\Services\slj\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C0073006C006A002E007300790073000000

Detected by UnHackMe:

SLJ.SYS
Default location: %SYSDIR%\DRIVERS\SLJ.SYS

Dropper information:
MD5: c5d811706076e3c7f26bcff8cc533fad
File size: 172288 bytes

Leave a Reply