Solved! Use NNIB.006 (KeyLogger Ardamax) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NNIB.006 – KeyLogger Ardamax removal

File MD5 Virus Alias
NNIB.006 43f02e9974b1477c1e6388882f233db0 KeyLogger Ardamax
NNIB.006 43f02e9974b1477c1e6388882f233db0 Trojan UnwantedProgram
NNIB.006 43f02e9974b1477c1e6388882f233db0 Trojan Eldorado

NNIB.006 size: 8192 bytes
NNIB.006 hash: 43F02E9974B1477C1E6388882F233DB0

Created files:

%SysDir%\28463\AKV.exe
%SysDir%\28463\NNIB.001
%SysDir%\28463\NNIB.002
%SysDir%\28463\NNIB.006
%SysDir%\28463\NNIB.007
%SysDir%\28463\NNIB.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NNIB Agent: %WinDir%\System32\28463\NNIB.exe

Detected by UnHackMe:

NNIB.006
Default location: %SYSDIR%\28463\NNIB.006

Dropper information:
MD5: 7bba5667d3a936549752fd7483b8c559
File size: 514824 bytes

Leave a Reply