Home Malware Programs Trojans Trojan-Spy.Ardamax!sd6

Trojan-Spy.Ardamax!sd6

Posted: September 1, 2011

Trojan-Spy.Ardamax!sd6 is a Trojan infection that can put a targeted computer or network in great danger. Trojan-Spy.Ardamax!sd6 spreads via malicious websites or corrupt files downloaded from an unidentified source. Once installed, Trojan-Spy.Ardamax!sd6 will communicate with a remote IRC server and enable an attacker to gain remote access to an affected computer system by registering ports. Trojan-Spy.Ardamax!sd6 can disable firewalls and gather its victim's personal information. Trojan-Spy.Ardamax!sd6 may slow down your PC and block you from accessing the Internet. Uninstall Trojan-Spy.Ardamax!sd6 as soon as possible to protect your machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CommonPrograms%\Ardamax Keylogger\Ardamax Keylogger.lnk File name: %CommonPrograms%\Ardamax Keylogger\Ardamax Keylogger.lnk
File type: Shortcut
Mime Type: unknown/lnk

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C7EF9D4-19EA-7714-8117-D2C4CFF4D200}\1.0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C7EF9D4-19EA-7714-8117-D2C4CFF4D200}\1.0\0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303EEA78-CF11-41F0-268A-DC602412A486}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303EEA78-CF11-41F0-268A-DC602412A486}\ControlHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303EEA78-CF11-41F0-268A-DC602412A486}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303EEA78-CF11-41F0-268A-DC602412A486}\MiscStatusHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{303EEA78-CF11-41F0-268A-DC602412A486}\ProgIDHKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ardamax KeyloggerHKEY_CURRENT_USER\Software\ASProtect\SpecData
Loading...