Solved! Use ARL.DLL (Backdoor Koutodoor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

ARL.DLL – Backdoor Koutodoor removal

File MD5 Virus Alias
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Backdoor Koutodoor
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Trojan Generic
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Trojan Eldorado
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Trojan Adload
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Trojan Agent
ARL.DLL f91184e7775cdb196dccdfc35aad9973 Trojan Crypt

ARL.DLL size: 53248 bytes
ARL.DLL hash: F91184E7775CDB196DCCDFC35AAD9973

Created files:

%SysDir%\arl.dll
%SysDir%\drivers\jgch.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\jgch\Type: 01000000
HKLM\System\CurrentControlSet\Services\jgch\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\jgch\DisplayName: jgch
HKLM\System\CurrentControlSet\Services\jgch\ImagePath: 730079007300740065006D00330032005C0064007200690076006500720073005C006A006700630068002E007300790073000000

Detected by UnHackMe:

ARL.DLL
Default location: %SYSDIR%\ARL.DLL

Dropper information:
MD5: 0f8667e916b266227c268e19d14fa2bf
File size: 87296 bytes

Leave a Reply