RLWA.007 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RLWA.007 – KeyLogger Ardamax removal

File MD5 Virus Alias
RLWA.007 b5a87d630436f958c6e1d82d15f98f96 KeyLogger Ardamax
RLWA.007 b5a87d630436f958c6e1d82d15f98f96 Trojan UnwantedProgram
RLWA.007 b5a87d630436f958c6e1d82d15f98f96 Trojan Genome
RLWA.007 b5a87d630436f958c6e1d82d15f98f96 Trojan Eldorado
RLWA.007 b5a87d630436f958c6e1d82d15f98f96 Trojan Agent

RLWA.007 size: 5632 bytes
RLWA.007 hash: B5A87D630436F958C6E1D82D15F98F96

Created files:

%SysDir%\28463\AKV.exe
%SysDir%\28463\RLWA.001
%SysDir%\28463\RLWA.006
%SysDir%\28463\RLWA.007
%SysDir%\28463\RLWA.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RLWA Agent: %WinDir%\System32\28463\RLWA.exe

Detected by UnHackMe:

RLWA.007
Default location: %SYSDIR%\28463\RLWA.007

Dropper information:
MD5: 4b39ed5b5baf28bbaca73393385b0e18
File size: 516864 bytes

Leave a Reply