Locate the directory it's running from (process manager, note the process that's running and search for it). Download
Unlocker Assistant and remove it along with other suspect and similarly named files. Make sure to look through and find these entries:
Code:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallArdamaxKeylogger
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsAppPathsakl.exe
HKEY_CURRENT_USERSoftwareArdamaxKeyloggerLite
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunNSK
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionUninstallArdamax Keylogger
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunArdamaxKeylogger
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsApp Pathsakl.exe
HKEY_CURRENT_USER SoftwareArdamax Keylogger Lite
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunNSK
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunArdamax Keylogger
A few searches found me that these are the active processes the Ardamax keylogger uses:
Code:
nsk.exe
akv.exe
akl.exe
akv.exe
nsk.exeakl.exe
Next you need to unregister the .dlls it uses
Copy and post the following into Run (Windows Key + R)
Code:
exact directory path + "regsvr32 /u" + kh.dll
Code:
exact directory path + "regsvr32 /u" + il.dll
I hope that helps :)
Edit: The following is a complete list of the files that you should be looking for (as far as I know this is all of them)
Code:
settings.ini
akv.ini
kh.dll
il.dll
nsk.exe
akv.exe
akl.exe
akv.exe
nsk.exe
il.dll
kh.dll
akv.ini
settings.iniakl.exe