RRE.001 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RRE.001 – KeyLogger Ardamax removal

File MD5 Virus Alias
RRE.001 1b5cf87fb26a702dc4d8e27ee488bfa1 KeyLogger Ardamax
RRE.001 1b5cf87fb26a702dc4d8e27ee488bfa1 Trojan Generic
RRE.001 1b5cf87fb26a702dc4d8e27ee488bfa1 Worm AMN
RRE.001 1b5cf87fb26a702dc4d8e27ee488bfa1 Trojan Graftor
RRE.001 1b5cf87fb26a702dc4d8e27ee488bfa1 Trojan Agent

RRE.001 size: 80384 bytes
RRE.001 hash: 1B5CF87FB26A702DC4D8E27EE488BFA1

Created files:

%SysDir%\IDMPTT\AKV.exe
%SysDir%\IDMPTT\RRE.001
%SysDir%\IDMPTT\RRE.002
%SysDir%\IDMPTT\RRE.004
%SysDir%\IDMPTT\RRE.005
%SysDir%\IDMPTT\RRE.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RRE Start: %WinDir%\System32\IDMPTT\RRE.exe

Detected by UnHackMe:

RRE.001
Default location: %SYSDIR%\IDMPTT\RRE.001

Dropper information:
MD5: 72741c9b6d5c83095d4cb742bfddaf8d
File size: 1724416 bytes

Leave a Reply