Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Application.Ardamax_Keylogger Ardamax Keylogger is a keystroke recorder that captures user's activity and saves it to an encrypted log file. The log file can be viewed with the powerful Log Viewer.
Application.Ardamax!ct Application.Ardamax!ct is a 100% legitimate application. Under certain circumstances, however, some people may find it undesirable.

Threat CategoryDescription
A spyware program that represents security risk for a local system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %CommonPrograms%\Ardamax Keylogger\Ardamax Keylogger.lnk 654 bytes MD5: 0xA3BA50403E05F4FB527C0685BF10AE38
SHA-1: 0x79662D27C8448B90DE5E563927BEE765B00DF676
(not available)
2 %System%\[filename of the sample #1 without extension].001 2,596 bytes MD5: 0xE6556A30989FAB19533FB98E065EBB3E
SHA-1: 0xEF8EF97197D2A7407A3C72A95C36BAF84CA7ECA1
(not available)
3 [file and pathname of the sample #1] 525,312 bytes MD5: 0x0C7A714B8E1D2EAD2AFC90DCC43BBE18
SHA-1: 0x66736613F22771F5DA5606ED8C80B572B3F5C103
Application.Ardamax!ct [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.ae [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
Win-Trojan/Xema.variant [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]544,768 bytes

 

Registry Modifications

 

Other details

Germany

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.