NGB.001 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NGB.001 – KeyLogger Ardamax removal

File MD5 Virus Alias
NGB.001 a15c556f17d7db8287e023138942d5db KeyLogger Ardamax
NGB.001 a15c556f17d7db8287e023138942d5db Trojan SuspiciousFile
NGB.001 a15c556f17d7db8287e023138942d5db Trojan Downloader

NGB.001 size: 61952 bytes
NGB.001 hash: A15C556F17D7DB8287E023138942D5DB

Created files:

%SysDir%\FYHAGF\AKV.exe
%SysDir%\FYHAGF\NGB.001
%SysDir%\FYHAGF\NGB.002
%SysDir%\FYHAGF\NGB.004
%SysDir%\FYHAGF\NGB.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NGB Start: %WinDir%\System32\FYHAGF\NGB.exe

Detected by UnHackMe:

NGB.001
Default location: %SYSDIR%\FYHAGF\NGB.001

Dropper information:
MD5: 6d42c3eff7332fce8bb5348b8fc5460f
File size: 3950080 bytes

Leave a Reply