RLWA.006 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RLWA.006 – KeyLogger Ardamax removal

File MD5 Virus Alias
RLWA.006 43f02e9974b1477c1e6388882f233db0 KeyLogger Ardamax
RLWA.006 43f02e9974b1477c1e6388882f233db0 Trojan UnwantedProgram
RLWA.006 43f02e9974b1477c1e6388882f233db0 Trojan Eldorado

RLWA.006 size: 8192 bytes
RLWA.006 hash: 43F02E9974B1477C1E6388882F233DB0

Created files:

%SysDir%\28463\AKV.exe
%SysDir%\28463\RLWA.001
%SysDir%\28463\RLWA.006
%SysDir%\28463\RLWA.007
%SysDir%\28463\RLWA.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RLWA Agent: %WinDir%\System32\28463\RLWA.exe

Detected by UnHackMe:

RLWA.006
Default location: %SYSDIR%\28463\RLWA.006

Dropper information:
MD5: 4b39ed5b5baf28bbaca73393385b0e18
File size: 516864 bytes

Leave a Reply