NGB.002 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NGB.002 – KeyLogger Ardamax removal

File MD5 Virus Alias
NGB.002 daabecdfba287a3333b60ae82211acd7 KeyLogger Ardamax
NGB.002 daabecdfba287a3333b60ae82211acd7 Trojan SuspiciousFile

NGB.002 size: 44544 bytes
NGB.002 hash: DAABECDFBA287A3333B60AE82211ACD7

Created files:

%SysDir%\FYHAGF\AKV.exe
%SysDir%\FYHAGF\NGB.001
%SysDir%\FYHAGF\NGB.002
%SysDir%\FYHAGF\NGB.004
%SysDir%\FYHAGF\NGB.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NGB Start: %WinDir%\System32\FYHAGF\NGB.exe

Detected by UnHackMe:

NGB.002
Default location: %SYSDIR%\FYHAGF\NGB.002

Dropper information:
MD5: 6d42c3eff7332fce8bb5348b8fc5460f
File size: 3950080 bytes

Leave a Reply