Solved! Use JLAR.EXE (KeyLogger Ardamax) Removal Guide

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

JLAR.EXE – KeyLogger Ardamax removal

File MD5 Virus Alias
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a KeyLogger Ardamax
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a Trojan (Suspicious File)
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a Trojan XPACK
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a Trojan Generic
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a Trojan DNAScan
JLAR.EXE c5ca2c96edc99cf9edf0f861d784209a Backdoor Bifrose

JLAR.EXE size: 663552 bytes
JLAR.EXE hash: C5CA2C96EDC99CF9EDF0F861D784209A

Created files:

%SysDir%\28463\AKV.exe
%SysDir%\28463\JLAR.001
%SysDir%\28463\JLAR.006
%SysDir%\28463\JLAR.007
%SysDir%\28463\JLAR.exe
%SysDir%\28463\key.bin

Detected by UnHackMe:

JLAR.EXE
Default location: %SYSDIR%\28463\JLAR.EXE

Dropper information:
MD5: c6c72edcbc5dc834e2dc9f6c5e542ade
File size: 827497 bytes