Threat Search: 

ThreatExpert's Statistics for Keylog-Ardamax.dll [McAfee]:

Keylog-Ardamax.dll [McAfee] is also known as:
Threat AliasNumber of Incidents
Spyware.Ardakey [Symantec]113,110
MonitoringTool:Win32/Ardamax [Microsoft]110,346
not-a-virus:Monitor.Win32.Ardamax.ae [Kaspersky Lab]100,609
Trojan-Spy.Ardamax.J [Ikarus]84,300
Application.Ardamax_Keylogger [PC Tools]61,464
Win-Trojan/Xema.variant [AhnLab]42,720
TrojanSpy.Ardamax.WQ [PC Tools]37,771
Application.Ardamax!ct [PC Tools]25,895
not-a-virus:Monitor.Win32.Ardamax.o [Kaspersky Lab]6,529
not-a-virus:Monitor.Win32.Ardamax.s [Kaspersky Lab]2,642
Application.Keylogger.Ardamax [Ikarus]2,365
RiskWare.Ardamax.AA [PC Tools]2,205
RiskWare.Ardamax.Z [PC Tools]2,205
Spyware.Ardakey!sd6 [PC Tools]2,101
not-a-virus:Monitor.Win32.Ardamax.ac [Kaspersky Lab]1,970
Spyware.Ardakey!sd5 [PC Tools]1,918
Win-Trojan/Ardamax.7680 [AhnLab]1,777
Virus.Win32.Ardamax.GG [Ikarus]1,429
not-a-virus:Monitor.Win32.Ardamax.r [Kaspersky Lab]1,331
not-a-virus:Monitor.Win32.Ardamax.w [Kaspersky Lab]1,192
Trojan-Dropper.Agent [PC Tools]1,104
not-a-virus:Monitor.Win32.Ardamax [Ikarus]1,065
Win-Trojan/Ardamax.484864 [AhnLab]1,056
not-a-virus:Monitor.Win32.Ardamax.o [Ikarus]1,023
RiksWare.Ardamax.Y [PC Tools]1,008
not-a-virus:Monitor.Win32.Ardamax.z [Kaspersky Lab]961
Mal/Generic-A [Sophos]821
not-a-virus:Monitor.Win32.Ardamax.271 [Kaspersky Lab]821
not-a-virus:Monitor.Win32.Ardamax.ah [Ikarus]804
TROJ_KEYLOG.EB [Trend Micro]637
Win-Trojan/Ardamax.404480 [AhnLab]630
Win-Trojan/Keylogger.5632.C [AhnLab]473
TrojanSpy:WinNT/Ardamax.A!sys [Microsoft]343
not-a-virus:Monitor.Win32.Ardamax.24 [Kaspersky Lab]335
RiskWare.ArdamaxView.A [PC Tools]324
not-a-virus:Monitor.Win32.Ardamax.hi [Kaspersky Lab]228
not-a-virus:Monitor.Win32.Ardamax.jk [Kaspersky Lab]221
not-a-virus:Monitor.Win32.Ardamax.24 [Ikarus]196
TrojanSpy.Ardamax.Gen.2 [PC Tools]153
Virus.Win32.Ardamax.CI [Ikarus]152
Spyware.Ardamax!sd5 [PC Tools]146
Win-Trojan/Ardamax.484864.B [AhnLab]144
TROJ_KEYLOGGE.AK [Trend Micro]140
Trojan-Spy.Win32.Ardamax.aci [Kaspersky Lab]125
Win-Trojan/Ardamax.5632.M [AhnLab]123
not-a-virus:Monitor.Win32.Ardamax.af [Kaspersky Lab]103
Trojan.Generic [Ikarus]101
Spyware.Ardakey [PC Tools]97
Trojan-Spy.Ardamax!sd5 [PC Tools]96
TrojanSpy.Ardamax.Gen [PC Tools]93
Virus.Win32.Ardamax.EK [Ikarus]89
MonitoringTool [Ikarus]88
Win-Trojan/Ardamax.5632.D [AhnLab]85
Win-Trojan/Ardamax.665088 [AhnLab]70
Trojan-Spy.Win32.Ardamax [Ikarus]68
Win-Trojan/Ardamax.417280 [AhnLab]66
not-a-virus:Monitor.Win32.Ardamax.25 [Kaspersky Lab]60
not-a-virus:Monitor.Win32.Ardamax.mh [Kaspersky Lab]58
not-a-virus:Monitor.Win32.Ardamax.25 [Ikarus]54
Win-Trojan/Ardamax.403456 [AhnLab]50
Trojan-Spy.Win32.Ardamax.e [Kaspersky Lab]49
not-a-virus:Monitor.Win32.Ardamax.e [Kaspersky Lab]38
not-a-virus:Monitor.Win32.Ardamax.gg [Kaspersky Lab]36
not-a-virus:Monitor.Win32.Ardamax.u [Kaspersky Lab]33
not-a-virus:Monitor.Win32.Ardamax.n [Kaspersky Lab]32
Trojan-Spy.Win32.Ardamax.t [Kaspersky Lab]32
Trojan-Spy.Win32.Ardamax.aol [Kaspersky Lab]31
Win-Trojan/Ardamax.5120 [AhnLab]31
Mal/Agent-Fam [Sophos]30
Win-Trojan/Ardamax.662016.B [AhnLab]30
Win-Trojan/Ardamax.3584 [AhnLab]28
not-a-virus:Monitor.Win32.Ardamax.dq [Kaspersky Lab]27
Trojan-Spy.Win32.Ardamax.d [Kaspersky Lab]27
Win-Trojan/Ardamax.4608.B [AhnLab]27
not-a-virus:Monitor.Win32.Ardamax.k [Kaspersky Lab]24
Trojan-Spy.Win32.Ardamax.le [Kaspersky Lab]24
Trojan-Spy.Win32.Ardamax.n [Kaspersky Lab]24
Win-Trojan/Ardamax.5632.F [AhnLab]24
Win-Trojan/Keylogger.470528.B [AhnLab]24
not-a-virus:Monitor.Win32.Ardamax.af [Ikarus]22
TSPY_ARDAMAX.CV [Trend Micro]18
Trojan-Spy.Win32.Ardamax.ahk [Kaspersky Lab]17
Win-Trojan/Ardamax.5120.B [AhnLab]17
not-a-virus:Monitor.Win32.Ardamax.dx [Kaspersky Lab]16
not-a-virus:Monitor.Win32.Ardamax.p [Kaspersky Lab]16
TROJ_Generic [Trend Micro]16
TSPY_ARDAMAX.CM [Trend Micro]16
Troj/Ardamax-N [Sophos]15
Trojan-Spy.Ardamax!sd6 [PC Tools]15
TrojanSpy:Win32/Ardamax.F [Microsoft]15
not-a-virus:Monitor.Win32.Ardamax.k [Ikarus]13
TrojanSpy.Ardamax.F [PC Tools]13
Win-Trojan/Keylogger.4608.C [AhnLab]13
not-a-virus:Monitor.Win32.Ardamax.20 [Kaspersky Lab]12
Win-Trojan/Agent.470528.G [AhnLab]12
Win-Trojan/Ardamax.525824.C [AhnLab]12
Suspicious.MH690 [Symantec]11
TSPY_ARDAMAX.HJ [Trend Micro]11
Trojan-Spy.Ardamax!ct [PC Tools]10
not-a-virus:Monitor.Win32.Ardamax.ee [Kaspersky Lab]9

Keylog-Ardamax.dll [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Germany379
Russian Federation74
United Kingdom5
Sweden2
Spain1

Keylog-Ardamax.dll [McAfee] is known to be created as:
%AppData%\csrss.exe
%LocalSettings%\carbon.exe
%ProgramFiles%\cle\akv.exe
%ProgramFiles%\cle\cle.exe
%ProgramFiles%\htv\akv.exe
%ProgramFiles%\htv\htv.exe
%ProgramFiles%\iwm\iwm.exe
%ProgramFiles%\pdm\akv.exe
%ProgramFiles%\pol\akv.exe
%ProgramFiles%\pol\pol.exe
%ProgramFiles%\rlg\akv.exe
%ProgramFiles%\rlg\rlg.exe
%ProgramFiles%\tnd\akv.exe
%ProgramFiles%\tnd\tnd.exe
%System%\28463\adub.exe
%System%\28463\adwc.exe
%System%\28463\aeln.exe
%System%\28463\akv.exe
%System%\28463\alni.exe
%System%\28463\aobo.exe
%System%\28463\aprr.exe
%System%\28463\aqlb.exe
%System%\28463\atbv.exe
%System%\28463\axdn.exe
%System%\28463\bolj.exe
%System%\28463\bqcd.exe
%System%\28463\cimr.exe
%System%\28463\cmxo.exe
%System%\28463\cnae.exe
%System%\28463\cpcr.exe
%System%\28463\cqiv.exe
%System%\28463\ctbk.exe
%System%\28463\dhtk.exe
%System%\28463\dmpu.exe
%System%\28463\dohi.exe
%System%\28463\dywu.exe
%System%\28463\eayp.exe
%System%\28463\ectg.exe
%System%\28463\ejwy.exe
%System%\28463\ekdd.exe
%System%\28463\eqfv.exe
%System%\28463\ernv.exe
%System%\28463\fooc.exe
%System%\28463\frqh.exe
%System%\28463\fvhk.exe
%System%\28463\gcuq.exe
%System%\28463\gxnp.exe
%System%\28463\gxuk.exe
%System%\28463\hdxx.exe
%System%\28463\hitv.exe
%System%\28463\hkdq.exe
%System%\28463\hkwo.exe
%System%\28463\hnsl.exe
%System%\28463\hqpt.exe
%System%\28463\hqqj.exe
%System%\28463\hyab.exe
%System%\28463\iihf.exe
%System%\28463\ioqy.exe
%System%\28463\itas.exe
%System%\28463\iurt.exe
%System%\28463\iylp.exe
%System%\28463\iypa.exe
%System%\28463\jevy.exe
%System%\28463\jpxe.exe
%System%\28463\jqal.exe
%System%\28463\jsjy.exe
%System%\28463\jvdb.exe
%System%\28463\kcww.exe
%System%\28463\kild.exe
%System%\28463\kilw.exe
%System%\28463\knmg.exe
%System%\28463\krgh.exe
%System%\28463\kuse.exe
%System%\28463\kyhf.exe
%System%\28463\lcoo.exe
%System%\28463\ldyv.exe
%System%\28463\lffl.exe
%System%\28463\lgue.exe
%System%\28463\lima.exe
%System%\28463\litw.exe
%System%\28463\ljxt.exe
%System%\28463\marr.exe
%System%\28463\mcpp.exe
%System%\28463\mkch.exe
%System%\28463\mlmv.exe
%System%\28463\mmsg.exe
%System%\28463\mmwa.exe
%System%\28463\mnas.exe
%System%\28463\msdd.exe
%System%\28463\muyx.exe
%System%\28463\mxlq.exe
%System%\28463\nhnv.exe
%System%\28463\nhpv.exe
%System%\28463\nitl.exe
%System%\28463\nulb.exe
%System%\28463\nwuh.exe
%System%\28463\ohbj.exe
%System%\28463\oimn.exe
%System%\28463\oiyu.exe
%System%\28463\ondj.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).