Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Spyware.Ardakey!sd6 Spyware.Ardakey!sd6 is a spyware program that represents security risk for your computer.

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\@2.tmp 633,286 bytes MD5: 0x0F613773493A81CE380F1339433CCCEB
SHA-1: 0x5DCFE49CFA7A5D86CDFC3CACB6B468F6853A4857
(not available)
2 %System%\28463\NSNO.001 386 bytes MD5: 0x7BB08760C7B342C996BD4B38D529D213
SHA-1: 0x62F31AFB89546ADB5D81E89374ACD4A9F095D744
(not available)
3 %System%\28463\NSNO.006 8,192 bytes MD5: 0x911A5A213762001178A48B2CEEFA1880
SHA-1: 0xDE9B25AC58E893397AB9AD3331BD922BBD5043AE
Spyware.Ardakey!sd6 [PCTools]
not-a-virus:Monitor.Win32.Ardamax.mh [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
MonitoringTool [Ikarus]
4 %System%\28463\NSNO.007 5,632 bytes MD5: 0x2183E6A435B000FC6E85B712513C3480
SHA-1: 0xC088B82494AAECA23A5ACFAF83F55597BD0BDC6E
Spyware.Ardakey!sd6 [PCTools]
not-a-virus:Monitor.Win32.Ardamax.o [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
not-a-virus:Monitor.Win32.Ardamax [Ikarus]
5 %System%\28463\NSNO.exe 616,960 bytes MD5: 0x8459B0BA642D016C60571A3AD31E6EC8
SHA-1: 0x19A7F23F7EEE39ED4217EC44EF46B899EABC32C2
Spyware.Ardakey!rem [PCTools]
Trojan-Spy.Win32.Ardamax.ahk [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
Mal/Generic-A [Sophos]
Trojan-Spy.Win32.Ardamax [Ikarus]
Win-Trojan/Ardamax.616960 [AhnLab]
packed with UPX [Kaspersky Lab]
6 [file and pathname of the sample #1] 647,168 bytes MD5: 0x50EDA6D5B2F76C9C408988487814322C
SHA-1: 0x89EFF9D5B65EC6E9FD5A4E1AC166A767FFDDF4BB
Application.Ardamax_Keylogger [PCTools]
Trojan-Spy.Win32.Ardamax.cko [Kaspersky Lab]
Spy-Agent.cv [McAfee]
TrojanSpy:Win32/Ardamax.BB [Microsoft]
Trojan-Spy.Win32.Ardamax [Ikarus]
Dropper/Downloader.817294 [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
NSNO.exe%System%\28463\NSNO.exe962,560 bytes

Process NameMain Module Size
NSNO.exe962,560 bytes

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.