HRV.EXE – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

HRV.EXE – KeyLogger Ardamax removal

File MD5 Virus Alias
HRV.EXE ed53cef3e425639f180392ccf031f9ce KeyLogger Ardamax
HRV.EXE ed53cef3e425639f180392ccf031f9ce Trojan Artemis
HRV.EXE ed53cef3e425639f180392ccf031f9ce Trojan Generic

HRV.EXE size: 1830400 bytes
HRV.EXE hash: ED53CEF3E425639F180392CCF031F9CE

Created files:

%SysDir%\WPNCTL\AKV.exe
%SysDir%\WPNCTL\HRV.001
%SysDir%\WPNCTL\HRV.002
%SysDir%\WPNCTL\HRV.004
%SysDir%\WPNCTL\HRV.005
%SysDir%\WPNCTL\HRV.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\HRV Start: %WinDir%\System32\WPNCTL\HRV.exe

Detected by UnHackMe:

HRV.EXE
Default location: %SYSDIR%\WPNCTL\HRV.EXE

Dropper information:
MD5: 5cec020d4d69dbe2ba4e595e7d6d8529
File size: 1729024 bytes

Leave a Reply