YFJ.001 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

YFJ.001 – KeyLogger Ardamax removal

File MD5 Virus Alias
YFJ.001 383d5f5d4240d590e7dec3f7312a4ac7 KeyLogger Ardamax
YFJ.001 383d5f5d4240d590e7dec3f7312a4ac7 Trojan Downloader
YFJ.001 383d5f5d4240d590e7dec3f7312a4ac7 Trojan CI

YFJ.001 size: 62464 bytes
YFJ.001 hash: 383D5F5D4240D590E7DEC3F7312A4AC7

Created files:

%SysDir%\MRDCKV\AKV.exe
%SysDir%\MRDCKV\YFJ.001
%SysDir%\MRDCKV\YFJ.002
%SysDir%\MRDCKV\YFJ.004
%SysDir%\MRDCKV\YFJ.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\YFJ Start: %WinDir%\System32\MRDCKV\YFJ.exe

Detected by UnHackMe:

YFJ.001
Default location: %SYSDIR%\MRDCKV\YFJ.001

Dropper information:
MD5: 33917ecdefc510eca026ecbfc3d33ef1
File size: 1217024 bytes

Leave a Reply