Home Malware Programs Keyloggers Trojan.Keylogger.Ardamax

Trojan.Keylogger.Ardamax

Posted: July 24, 2009

Threat Metric

Ranking: 6,779
Threat Level: 8/10
Infected PCs: 23,868
First Seen: July 24, 2009
Last Seen: October 7, 2023
OS(es) Affected: Windows

Trojan.Keylogger.Ardamax is a threatening program that allows con artists to record all keystrokes on the infected computer. However, this is just one of Trojan.Keylogger.Ardamax's primary features, and users whose computers get infected with Trojan.Keylogger.Ardamax may lose other important information as well.

Trojan.Keylogger.Ardamax is compatible with Windows 2000 and all newer versions, and it is currently being sold as a legitimate software product. However, Trojan.Keylogger.Ardamax may be used for harmful purposes because of its ability to install itself on computers silently and remain hidden for as long as necessary. Trojan.Keylogger.Ardamax is fully active while being hidden, and its operator can use the threat's control panel to carry out a long list of operations on the victim's computer – recording keystrokes, capturing browser activities, recording via the webcam, gathering e-mails, uploading/downloading files, microphone recording, chat monitoring and visual surveillance are just some of the Trojan.Keylogger.Ardamax's features that may be used for malicious purposes.

Since Trojan.Keylogger.Ardamax is being sold freely, there's no way to tell the exact distribution techniques used to spread this threat. Regardless of the propagation method used, it is certain that the best protection against Trojan.Keylogger.Ardamax and similar threats is to use a reliable antivirus software suite that offers active and passive protection modules to keep you safe online.

Aliases

W32/Gbot.YRA!tr.bdr [Fortinet]SPR/Tool.Ardamax.556 [AntiVir]Backdoor.Win32.Gbot.yra [Kaspersky]Artemis!647F311B4718 [McAfee]Ardamax.BUD [AVG]MemScan:Trojan.Generic.8306227 [BitDefender]Win32:Ardamax-PU [PUP] [Avast]Artemis!3DEBCBACE7A0 [McAfee]Ardamax.BWQ [AVG]Trojan.KeyLogger.18881 [DrWeb]Artemis!D7BB86DA5866 [McAfee]Trojan.KeyLogger.19070 [DrWeb]Trojan.KeyLogger.16596 [DrWeb]Win32:Ardamax-QG [PUP] [Avast]SPR/Tool.Monitor.Gen [AntiVir]
More aliases (498)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\YEY\YEY.exe File name: YEY.exe
Size: 1.79 MB (1793024 bytes)
MD5: 53522c8c3b01191caae1e1e2692c42de
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\YEY
Group: Malware file
Last Updated: January 8, 2013
%PROGRAMFILES%\JTF\JTF.exe File name: JTF.exe
Size: 1.53 MB (1531904 bytes)
MD5: ce6e2998fc31ef25e3771cd7be4f4e75
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\JTF
Group: Malware file
Last Updated: March 12, 2013
C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe File name: setup_akl64 (password=ardamax).exe
Size: 2.06 MB (2065604 bytes)
MD5: e33b737b368c02ef9b7c908c9472dfef
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
Group: Malware file
Last Updated: April 30, 2022
%PROGRAMFILES(x86)%\Ardamax\DFC.exe File name: DFC.exe
Size: 1.81 MB (1819648 bytes)
MD5: b37aad7a36fbbb2d2054e082d590a76c
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Ardamax
Group: Malware file
Last Updated: April 3, 2020
C:\Windows\SysWOW64\28463\AKV.exe File name: AKV.exe
Size: 404.48 KB (404480 bytes)
MD5: b8fa30233794772b8b76b4b1d91c7321
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SysWOW64\28463\AKV.exe
Group: Malware file
Last Updated: December 1, 2022
C:\WINDOWS\SysWOW64\FXVDEA\LYA.exe File name: LYA.exe
Size: 1.74 MB (1747968 bytes)
MD5: 3cd29c0df98a7aeb69a9692843ca3edb
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\SysWOW64\FXVDEA\LYA.exe
Group: Malware file
Last Updated: March 3, 2023
C:\WINDOWS\SysWOW64\FXVDEA\AKV.exe File name: AKV.exe
Size: 467.45 KB (467456 bytes)
MD5: 51507d91d43683b9c4b8fafeb4d888f8
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\SysWOW64\FXVDEA\AKV.exe
Group: Malware file
Last Updated: March 3, 2023
%PROGRAMFILES(x86)%\CSJ\CSJ.exe File name: CSJ.exe
Size: 1.8 MB (1801728 bytes)
MD5: 16a7080bdbdd3c66f6edef08c5bea843
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\CSJ
Group: Malware file
Last Updated: October 9, 2012
%PROGRAMFILES(x86)%\ETK\ETK.exe File name: ETK.exe
Size: 1.83 MB (1838080 bytes)
MD5: 56dce36cac37d632bf722e9804e4965e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ETK
Group: Malware file
Last Updated: October 17, 2012
C:\Windows\SysWOW64\WLGGBN\BCR.exe File name: BCR.exe
Size: 1.82 MB (1829888 bytes)
MD5: b910f5d24e399a13f6aae20535ac05b4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SysWOW64\WLGGBN\BCR.exe
Group: Malware file
Last Updated: August 14, 2022
C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe File name: setup_akl64 (password=ardamax).exe
Size: 2.13 MB (2139332 bytes)
MD5: e3d267c02ec24bd475e394551cca6ad0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\setup_akl64 (password=ardamax).exe
Group: Malware file
Last Updated: October 15, 2021
%PROGRAMFILES(x86)%\MAI\MAI.exe File name: MAI.exe
Size: 1.83 MB (1830400 bytes)
MD5: e40fa583acd317b71575596bd8bc10b8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\MAI
Group: Malware file
Last Updated: August 27, 2012
%USERPROFILE%\Desktop\ketlog\MSQ\MSQ.exe File name: MSQ.exe
Size: 1.82 MB (1829888 bytes)
MD5: f22340c8c0caad1136de9bec84c82281
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop\ketlog\MSQ
Group: Malware file
Last Updated: August 11, 2020
%WINDIR%\system32\NWXJWM\ELU.exe File name: ELU.exe
Size: 1.83 MB (1830400 bytes)
MD5: 785197d7f66a482b64c5ae297016d24e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\NWXJWM
Group: Malware file
Last Updated: October 30, 2012
%PROGRAMFILES(x86)%\POL\POL.exe File name: POL.exe
Size: 616.96 KB (616960 bytes)
MD5: 8459b0ba642d016c60571a3ad31e6ec8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\POL
Group: Malware file
Last Updated: November 21, 2019
f:\pendrive blanca\setup_akl (password=ardamax).exe File name: setup_akl (password=ardamax).exe
Size: 1.82 MB (1825918 bytes)
MD5: 725f36560115d2a096df3e499d6ba449
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: f:\pendrive blanca
Group: Malware file
Last Updated: October 15, 2021
%WINDIR%\system32\Sys\TND.exe File name: TND.exe
Size: 470.52 KB (470528 bytes)
MD5: a6c12264242dba831b32523a07688d4a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\Sys
Group: Malware file
Last Updated: March 29, 2013
%WINDIR%\SysWOW64\YAINGK\QHI.exe File name: QHI.exe
Size: 1.83 MB (1830400 bytes)
MD5: d5918580ed2951ab6b1a5a94719757ff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\YAINGK
Group: Malware file
Last Updated: March 29, 2013
%ALLUSERSPROFILE%\FYB\FYB.exe File name: FYB.exe
Size: 1.79 MB (1794560 bytes)
MD5: 14f067c0291ce6a4a4c4735ba7f4712d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\FYB
Group: Malware file
Last Updated: March 4, 2013
%WINDIR%\SysWOW64\LJXVCN\NGK.exe File name: NGK.exe
Size: 1.54 MB (1544192 bytes)
MD5: 0aaffc12ef1b416b9276bdc3fdec9dff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\LJXVCN
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\SysWOW64\ACDYGC\HWF.exe File name: HWF.exe
Size: 1.82 MB (1829888 bytes)
MD5: 647f311b471810298c1d0b3b43966d8c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\ACDYGC
Group: Malware file
Last Updated: May 13, 2013

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathsetup (password=ardamax).exeRegexp file mask%APPDATA%\support\svchost.exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Ardamax Keylogger

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\auk%ALLUSERSPROFILE%\cve%WINDIR%\Syswow64\sys32%WINDIR%\system32\sys32
Loading...