Threat Search: 

ThreatExpert's Statistics for TrojanSpy:Win32/Ardamax.D [Microsoft]:

TrojanSpy:Win32/Ardamax.D [Microsoft] is also known as:
Threat AliasNumber of Incidents
Spy-Agent.cv [McAfee]29
Trojan-Spy.Win32.Ardamax.t [Kaspersky Lab]29
TSPY_ARDAMAX.HR [Trend Micro]29
Suspicious.MH690 [Symantec]15
Win32.SuspectCrc [Ikarus]13
Dropper/Downloader.817294 [AhnLab]10
Spyware.Ardakey [Symantec]9
Trojan-Spy.Win32.Ardamax [Ikarus]8
Mal/Generic-A [Sophos]6
TrojanSpy.Ardamax.HZ [PC Tools]6
Win-Trojan/Ardamax.14848.E [AhnLab]5
TrojanSpy.Ardamax.BI [PC Tools]3
Application.Ardamax_Keylogger [PC Tools]1
Trojan-Spy.Ardamax!sd6 [PC Tools]1

TrojanSpy:Win32/Ardamax.D [Microsoft] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation18
Germany1
Netherlands1

TrojanSpy:Win32/Ardamax.D [Microsoft] is known to be created as:
%Temp%\file3.exe
Note: %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).