Trojan.Keylogger.Ardamax
Posted: July 24, 2009
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 6,779 |
---|---|
Threat Level: | 8/10 |
Infected PCs: | 23,868 |
First Seen: | July 24, 2009 |
---|---|
Last Seen: | October 7, 2023 |
OS(es) Affected: | Windows |
Trojan.Keylogger.Ardamax is a threatening program that allows con artists to record all keystrokes on the infected computer. However, this is just one of Trojan.Keylogger.Ardamax's primary features, and users whose computers get infected with Trojan.Keylogger.Ardamax may lose other important information as well.
Trojan.Keylogger.Ardamax is compatible with Windows 2000 and all newer versions, and it is currently being sold as a legitimate software product. However, Trojan.Keylogger.Ardamax may be used for harmful purposes because of its ability to install itself on computers silently and remain hidden for as long as necessary. Trojan.Keylogger.Ardamax is fully active while being hidden, and its operator can use the threat's control panel to carry out a long list of operations on the victim's computer – recording keystrokes, capturing browser activities, recording via the webcam, gathering e-mails, uploading/downloading files, microphone recording, chat monitoring and visual surveillance are just some of the Trojan.Keylogger.Ardamax's features that may be used for malicious purposes.
Since Trojan.Keylogger.Ardamax is being sold freely, there's no way to tell the exact distribution techniques used to spread this threat. Regardless of the propagation method used, it is certain that the best protection against Trojan.Keylogger.Ardamax and similar threats is to use a reliable antivirus software suite that offers active and passive protection modules to keep you safe online.
Aliases
More aliases (498)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%PROGRAMFILES%\YEY\YEY.exe
File name: YEY.exeSize: 1.79 MB (1793024 bytes)
MD5: 53522c8c3b01191caae1e1e2692c42de
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\YEY
Group: Malware file
Last Updated: January 8, 2013
%PROGRAMFILES%\JTF\JTF.exe
File name: JTF.exeSize: 1.53 MB (1531904 bytes)
MD5: ce6e2998fc31ef25e3771cd7be4f4e75
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\JTF
Group: Malware file
Last Updated: March 12, 2013
C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
File name: setup_akl64 (password=ardamax).exeSize: 2.06 MB (2065604 bytes)
MD5: e33b737b368c02ef9b7c908c9472dfef
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
Group: Malware file
Last Updated: April 30, 2022
%PROGRAMFILES(x86)%\Ardamax\DFC.exe
File name: DFC.exeSize: 1.81 MB (1819648 bytes)
MD5: b37aad7a36fbbb2d2054e082d590a76c
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Ardamax
Group: Malware file
Last Updated: April 3, 2020
C:\Windows\SysWOW64\28463\AKV.exe
File name: AKV.exeSize: 404.48 KB (404480 bytes)
MD5: b8fa30233794772b8b76b4b1d91c7321
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SysWOW64\28463\AKV.exe
Group: Malware file
Last Updated: December 1, 2022
C:\WINDOWS\SysWOW64\FXVDEA\LYA.exe
File name: LYA.exeSize: 1.74 MB (1747968 bytes)
MD5: 3cd29c0df98a7aeb69a9692843ca3edb
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\SysWOW64\FXVDEA\LYA.exe
Group: Malware file
Last Updated: March 3, 2023
C:\WINDOWS\SysWOW64\FXVDEA\AKV.exe
File name: AKV.exeSize: 467.45 KB (467456 bytes)
MD5: 51507d91d43683b9c4b8fafeb4d888f8
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\SysWOW64\FXVDEA\AKV.exe
Group: Malware file
Last Updated: March 3, 2023
%PROGRAMFILES(x86)%\CSJ\CSJ.exe
File name: CSJ.exeSize: 1.8 MB (1801728 bytes)
MD5: 16a7080bdbdd3c66f6edef08c5bea843
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\CSJ
Group: Malware file
Last Updated: October 9, 2012
%PROGRAMFILES(x86)%\ETK\ETK.exe
File name: ETK.exeSize: 1.83 MB (1838080 bytes)
MD5: 56dce36cac37d632bf722e9804e4965e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ETK
Group: Malware file
Last Updated: October 17, 2012
C:\Windows\SysWOW64\WLGGBN\BCR.exe
File name: BCR.exeSize: 1.82 MB (1829888 bytes)
MD5: b910f5d24e399a13f6aae20535ac05b4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SysWOW64\WLGGBN\BCR.exe
Group: Malware file
Last Updated: August 14, 2022
C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
File name: setup_akl64 (password=ardamax).exeSize: 2.13 MB (2139332 bytes)
MD5: e3d267c02ec24bd475e394551cca6ad0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
Group: Malware file
Last Updated: October 15, 2021
%PROGRAMFILES(x86)%\MAI\MAI.exe
File name: MAI.exeSize: 1.83 MB (1830400 bytes)
MD5: e40fa583acd317b71575596bd8bc10b8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\MAI
Group: Malware file
Last Updated: August 27, 2012
%USERPROFILE%\Desktop\ketlog\MSQ\MSQ.exe
File name: MSQ.exeSize: 1.82 MB (1829888 bytes)
MD5: f22340c8c0caad1136de9bec84c82281
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop\ketlog\MSQ
Group: Malware file
Last Updated: August 11, 2020
%WINDIR%\system32\NWXJWM\ELU.exe
File name: ELU.exeSize: 1.83 MB (1830400 bytes)
MD5: 785197d7f66a482b64c5ae297016d24e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\NWXJWM
Group: Malware file
Last Updated: October 30, 2012
%PROGRAMFILES(x86)%\POL\POL.exe
File name: POL.exeSize: 616.96 KB (616960 bytes)
MD5: 8459b0ba642d016c60571a3ad31e6ec8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\POL
Group: Malware file
Last Updated: November 21, 2019
f:\pendrive blanca\setup_akl (password=ardamax).exe
File name: setup_akl (password=ardamax).exeSize: 1.82 MB (1825918 bytes)
MD5: 725f36560115d2a096df3e499d6ba449
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: f:\pendrive blanca
Group: Malware file
Last Updated: October 15, 2021
%WINDIR%\system32\Sys\TND.exe
File name: TND.exeSize: 470.52 KB (470528 bytes)
MD5: a6c12264242dba831b32523a07688d4a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\Sys
Group: Malware file
Last Updated: March 29, 2013
%WINDIR%\SysWOW64\YAINGK\QHI.exe
File name: QHI.exeSize: 1.83 MB (1830400 bytes)
MD5: d5918580ed2951ab6b1a5a94719757ff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\YAINGK
Group: Malware file
Last Updated: March 29, 2013
%ALLUSERSPROFILE%\FYB\FYB.exe
File name: FYB.exeSize: 1.79 MB (1794560 bytes)
MD5: 14f067c0291ce6a4a4c4735ba7f4712d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\FYB
Group: Malware file
Last Updated: March 4, 2013
%WINDIR%\SysWOW64\LJXVCN\NGK.exe
File name: NGK.exeSize: 1.54 MB (1544192 bytes)
MD5: 0aaffc12ef1b416b9276bdc3fdec9dff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\LJXVCN
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\SysWOW64\ACDYGC\HWF.exe
File name: HWF.exeSize: 1.82 MB (1829888 bytes)
MD5: 647f311b471810298c1d0b3b43966d8c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\ACDYGC
Group: Malware file
Last Updated: May 13, 2013
More files
Registry Modifications
File name without pathsetup (password=ardamax).exeRegexp file mask%APPDATA%\support\svchost.exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Ardamax Keylogger
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.