HRV.002 – KeyLogger Ardamax

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

HRV.002 – KeyLogger Ardamax removal

File MD5 Virus Alias
HRV.002 5a5b9d9396603a17fa29160ace1a4595 KeyLogger Ardamax
HRV.002 5a5b9d9396603a17fa29160ace1a4595 Trojan SuspiciousFile
HRV.002 5a5b9d9396603a17fa29160ace1a4595 Trojan Generic
HRV.002 5a5b9d9396603a17fa29160ace1a4595 Trojan Click
HRV.002 5a5b9d9396603a17fa29160ace1a4595 Trojan Agent

HRV.002 size: 56320 bytes
HRV.002 hash: 5A5B9D9396603A17FA29160ACE1A4595

Created files:

%SysDir%\WPNCTL\AKV.exe
%SysDir%\WPNCTL\HRV.001
%SysDir%\WPNCTL\HRV.002
%SysDir%\WPNCTL\HRV.004
%SysDir%\WPNCTL\HRV.005
%SysDir%\WPNCTL\HRV.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HRV Start: %WinDir%\System32\WPNCTL\HRV.exe

Detected by UnHackMe:

HRV.002
Default location: %SYSDIR%\WPNCTL\HRV.002

Dropper information:
MD5: 5cec020d4d69dbe2ba4e595e7d6d8529
File size: 1729024 bytes

Leave a Reply