NGB.EXE – KeyLogger Ardamax

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

NGB.EXE – KeyLogger Ardamax removal

File MD5 Virus Alias
NGB.EXE f3819a6cab8ae058254c4abb3844d87e KeyLogger Ardamax
NGB.EXE f3819a6cab8ae058254c4abb3844d87e Trojan SuspiciousFile
NGB.EXE f3819a6cab8ae058254c4abb3844d87e Trojan Artemis
NGB.EXE f3819a6cab8ae058254c4abb3844d87e Trojan Downloader
NGB.EXE f3819a6cab8ae058254c4abb3844d87e Trojan Agent

NGB.EXE size: 1748480 bytes
NGB.EXE hash: F3819A6CAB8AE058254C4ABB3844D87E

Created files:

%SysDir%\FYHAGF\AKV.exe
%SysDir%\FYHAGF\NGB.001
%SysDir%\FYHAGF\NGB.002
%SysDir%\FYHAGF\NGB.004
%SysDir%\FYHAGF\NGB.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NGB Start: %WinDir%\System32\FYHAGF\NGB.exe

Detected by UnHackMe:

NGB.EXE
Default location: %SYSDIR%\FYHAGF\NGB.EXE

Dropper information:
MD5: 6d42c3eff7332fce8bb5348b8fc5460f
File size: 3950080 bytes

Leave a Reply