Sonicwall Signatures


Go to All Categories list.

Ardamax.NBQ_6 is an Adware. Adware, or advertising-supported software, is any software that automatically renders advertisements in order to generate revenue for its author. The advertisements may be in the user interface of the software or on a screen presented to the user during the installation process. It is usually annoying but harmless, unless it is combined with spyware or trackware.

File Related Changes
It drops the following file(s) on the system:
  • "c:\Users\Admin\AppData\Local\Temp\ztmp\t25841.bat"
  • "c:\ProgramData\DNFDMV\LLB.exe"
  • "c:\Users\Admin\AppData\Local\Temp\ztmp\t25874.exe"
  • "c:\Users\Admin\AppData\Local\Temp\afolder\1.exe"

    Process Related Changes
    It creates the following process(es):
    • C:\Windows\system32\cmd.exe [ 1.exe ]
    • C:\ProgramData\DNFDMV\LLB.exe
    • C:\Users\Admin\AppData\Local\Temp\afolder\1.exe [ 1.exe ]

        Registry Related Changes
        It makes the following registry modifications to ensure infection after system reboot:
        • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\llbstart = C:\ProgramData\DNFDMV\LLB.exe

        Relevant Information