RRE.EXE – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RRE.EXE – KeyLogger Ardamax removal

File MD5 Virus Alias
RRE.EXE 7f9e58f1df8721ed17066d08a769c73a KeyLogger Ardamax
RRE.EXE 7f9e58f1df8721ed17066d08a769c73a Trojan Artemis
RRE.EXE 7f9e58f1df8721ed17066d08a769c73a Trojan Generic
RRE.EXE 7f9e58f1df8721ed17066d08a769c73a Worm AMN
RRE.EXE 7f9e58f1df8721ed17066d08a769c73a Trojan Agent

RRE.EXE size: 1829888 bytes
RRE.EXE hash: 7F9E58F1DF8721ED17066D08A769C73A

Created files:

%SysDir%\IDMPTT\AKV.exe
%SysDir%\IDMPTT\RRE.001
%SysDir%\IDMPTT\RRE.002
%SysDir%\IDMPTT\RRE.004
%SysDir%\IDMPTT\RRE.005
%SysDir%\IDMPTT\RRE.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RRE Start: %WinDir%\System32\IDMPTT\RRE.exe

Detected by UnHackMe:

RRE.EXE
Default location: %SYSDIR%\IDMPTT\RRE.EXE

Dropper information:
MD5: 72741c9b6d5c83095d4cb742bfddaf8d
File size: 1724416 bytes

Leave a Reply