Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A spyware program that represents security risk for a local system
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\@2.tmp 906,224 bytes MD5: 0x0C200EA6CB6025EF02E6CF1E584B5A62
SHA-1: 0xD3C3BF614C113734332187E2FABE68C080FFF009
Application.Ardamax_Keylogger [PCTools]
Virus.Win32.Ardamax [Ikarus]
2 %System%\28463\AKV.exe 404,480 bytes MD5: 0xD63CC8679A63448DB1C64252E14E4AB5
SHA-1: 0x10B3A9AC4BC16E8AC1CD05E50B4D540FA3EF223E
Application.Ardamax_Keylogger [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.r [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
Mal/Generic-A [Sophos]
MonitoringTool:Win32/Ardamax [Microsoft]
not-a-virus:Monitor.Win32.Ardamax.ah [Ikarus]
Win-Trojan/Ardamax.404480 [AhnLab]
3 %System%\28463\QJPS.001 412 bytes MD5: 0x3F075F0C47F9030F2FA79E85C9E2192D
SHA-1: 0x8ED722D4F1EDF766828A933050878F738ED99CE9
(not available)
4 %System%\28463\QJPS.002 1,072 bytes MD5: 0x1CF8AE30AA4A423ECAAB833DCD24BE41
SHA-1: 0x66801B9D61A698DC04F23B2244FEE2CC4323C4FA
(not available)
5 %System%\28463\QJPS.006 8,192 bytes MD5: 0x81E20F4361CF8F5A57812871C24D945E
SHA-1: 0x5D7877D6959AB26599B05795A71633F00C37A3DA
Spyware.Ardakey!sd6 [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.r [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
not-a-virus:Monitor.Win32.Ardamax [Ikarus]
Win-Trojan/Ardamax.7680 [AhnLab]
6 %System%\28463\QJPS.007 5,632 bytes MD5: 0xE9FBDCC2F5FB657FA519B3F5C69FC52D
SHA-1: 0xC49CCA77B46A59D620711DE7564D43E5DAFCD2B5
Spyware.Ardakey!sd6 [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.o [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
not-a-virus:Monitor.Win32.Ardamax.o [Ikarus]
7 %System%\28463\QJPS.exe 484,864 bytes MD5: 0x97D8AD45F48B4B28A93AAB94699B7168
SHA-1: 0x8B69B7FD7C008B95D12386F6DA415097E72151DE
Spyware.Ardakey!sd6 [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.o [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
Mal/Generic-A [Sophos]
MonitoringTool:Win32/Ardamax [Microsoft]
Trojan-Spy.Ardamax.J [Ikarus]
Win-Trojan/Ardamax.484864.B [AhnLab]
8 [file and pathname of the sample #1] 495,154 bytes MD5: 0xDF6BA5A5CE82264EAC39F1A627BE9FF3
SHA-1: 0x94CB2BA6332FE8C418A2AA02F8364789C9C5019E
Application.Ardamax_Keylogger [PCTools]
Suspicious.MH690 [Symantec]
Trojan-Spy.Win32.Ardamax.t [Kaspersky Lab]
Spy-Agent.cv [McAfee]
TSPY_ARDAMAX.HR [Trend Micro]
TrojanSpy:Win32/Ardamax.N [Microsoft]
Trojan-Spy.Win32.Ardamax [Ikarus]
Dropper/Downloader.817294 [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
QJPS.exe%System%\28463\QJPS.exe503,808 bytes

Process NameMain Module Size
QJPS.exe503,808 bytes

 

Other details

Russian Federation

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.