HRV.001 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

HRV.001 – KeyLogger Ardamax removal

File MD5 Virus Alias
HRV.001 c05aeb763f41d54b25865ed649ab7454 KeyLogger Ardamax
HRV.001 c05aeb763f41d54b25865ed649ab7454 Trojan Graftor
HRV.001 c05aeb763f41d54b25865ed649ab7454 Trojan Agent

HRV.001 size: 80384 bytes
HRV.001 hash: C05AEB763F41D54B25865ED649AB7454

Created files:

%SysDir%\WPNCTL\AKV.exe
%SysDir%\WPNCTL\HRV.001
%SysDir%\WPNCTL\HRV.002
%SysDir%\WPNCTL\HRV.004
%SysDir%\WPNCTL\HRV.005
%SysDir%\WPNCTL\HRV.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HRV Start: %WinDir%\System32\WPNCTL\HRV.exe

Detected by UnHackMe:

HRV.001
Default location: %SYSDIR%\WPNCTL\HRV.001

Dropper information:
MD5: 5cec020d4d69dbe2ba4e595e7d6d8529
File size: 1729024 bytes

Leave a Reply