SWK.01 – KeyLogger Ardamax

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

SWK.01 – KeyLogger Ardamax removal

File MD5 Virus Alias
SWK.01 8942289fe2d65d66fb8bbbd8f5f1bd5b KeyLogger Ardamax
SWK.01 8942289fe2d65d66fb8bbbd8f5f1bd5b Trojan Generic
SWK.01 8942289fe2d65d66fb8bbbd8f5f1bd5b Trojan CI
SWK.01 8942289fe2d65d66fb8bbbd8f5f1bd5b Trojan Agent

SWK.01 size: 80384 bytes
SWK.01 hash: 8942289FE2D65D66FB8BBBD8F5F1BD5B

Created files:

%AppData%\SSENEX\SWK.00
%AppData%\SSENEX\SWK.01
%AppData%\SSENEX\SWK.02
%AppData%\SSENEX\SWK.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SWK Start: %WinDir%\System32\config\Systemprofile\Application Data\SSENEX\SWK.exe

Detected by UnHackMe:

SWK.01
Default location: %APPDATA%\SSENEX\SWK.01

Dropper information:
MD5: 4a342804dd7896914a00b94cbcaca213
File size: 1686528 bytes

Leave a Reply