Dmitry Sokolov recommends UnHackMe!
UnHackMe is a powerful tool against malware.UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!
Monitor.Win32.Ardamax.cip also known as TR/Ardamax.D, TROJ_GEN.R0CBH07I313, W32/Trojan.WRUI-8123.
Malware Analysis of Monitor.Win32.Ardamax.cip
Created files:
%Common Desktopdirectory%\omixdmvn.txt
%Common Desktopdirectory%\whrryggn.bat
%SysDir%\cfwin32.dll
%SysDir%\csrss32.dll
%SysDir%\csrss64.dll
%SysDir%\default2.sfx
%SysDir%\NoSafeMode.dll
%SysDir%\nsf.exe
%SysDir%\sdelete.dll
%SysDir%\svschost.exe
C:\abwvrpcm\svchost.exe
C:\plbbqirj\dc.exe
C:\ProgramData\cbojrhub\svchost.exe
C:\ProgramData\kxhafmyp\svchost.exe
C:\ProgramData\rkbttpwo\nprkyfbl.dlls
C:\ProgramData\rkbttpwo\qqcrwxmn.dlls
C:\ProgramData\stppthmain\stppthmain.dll
C:\ProgramData\tklidtjy\eifiodcn.dll
C:\ProgramData\tklidtjy\eifiodcn.dll.dlls
C:\ProgramData\tklidtjy\xwhljjdr.dll
Detected by UnHackMe:
NSF.EXE
Default location: %SYSDIR%\NSF.EXE
UnHackMe
removes malware invisible for your antivirus!
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.