SWK.EXE – KeyLogger Ardamax

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

SWK.EXE – KeyLogger Ardamax removal

File MD5 Virus Alias
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 KeyLogger Ardamax
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 Trojan SuspiciousFile
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 Trojan Artemis
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 Trojan Generic
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 Trojan Downloader
SWK.EXE 3710bdb7e3ba37a6773e2f9920bb0d94 Trojan Agent

SWK.EXE size: 2189824 bytes
SWK.EXE hash: 3710BDB7E3BA37A6773E2F9920BB0D94

Created files:

%AppData%\SSENEX\SWK.00
%AppData%\SSENEX\SWK.01
%AppData%\SSENEX\SWK.02
%AppData%\SSENEX\SWK.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SWK Start: %WinDir%\System32\config\Systemprofile\Application Data\SSENEX\SWK.exe

Detected by UnHackMe:

SWK.EXE
Default location: %APPDATA%\SSENEX\SWK.EXE

Dropper information:
MD5: 4a342804dd7896914a00b94cbcaca213
File size: 1686528 bytes

Leave a Reply