Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A spyware program that represents security risk for a local system
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\@2.tmp 1,102,274 bytes MD5: 0x0F32D47596E4772E6138EBE2F7C6CDA2
SHA-1: 0x0EE28A8399972CBEB05C1AC92FA3E311780B4789
Spyware.Ardakey [Symantec]
2 %System%\28463\AKV.exe 468,480 bytes MD5: 0x752E814C2A5D197B8065501E786683C9
SHA-1: 0xC7B5840AB79EC308D0ACA9A8F07D59730B31AD99
Application.Ardamax_Keylogger [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.va [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
Mal/Generic-L [Sophos]
MonitoringTool:Win32/Ardamax [Microsoft]
Trojan.Generic [Ikarus]
3 %System%\28463\QERN.001 366 bytes MD5: 0x915603E3E84A4EE4800AA962BF369DA2
SHA-1: 0xE2E3E037589463DAF915DD1091FF6E29BC13390F
(not available)
4 %System%\28463\QERN.002 1,072 bytes MD5: 0x20C8070962D3B05C062D81D90F375333
SHA-1: 0x238E52A9A793D06533ED11ECBE132983EC733BD6
(not available)
5 %System%\28463\QERN.006 8,192 bytes MD5: 0x911A5A213762001178A48B2CEEFA1880
SHA-1: 0xDE9B25AC58E893397AB9AD3331BD922BBD5043AE
Spyware.Ardakey!sd6 [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.mh [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
MonitoringTool [Ikarus]
6 %System%\28463\QERN.007 5,632 bytes MD5: 0x2183E6A435B000FC6E85B712513C3480
SHA-1: 0xC088B82494AAECA23A5ACFAF83F55597BD0BDC6E
Spyware.Ardakey!sd6 [PCTools]
Spyware.Ardakey [Symantec]
not-a-virus:Monitor.Win32.Ardamax.o [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
MonitoringTool:Win32/Ardamax [Microsoft]
Virus.Win32.Ardamax.GG [Ikarus]
7 %System%\28463\QERN.exe 616,960 bytes MD5: 0x8459B0BA642D016C60571A3AD31E6EC8
SHA-1: 0x19A7F23F7EEE39ED4217EC44EF46B899EABC32C2
Spyware.Ardakey!rem [PCTools]
Spyware.Ardakey [Symantec]
Trojan-Spy.Win32.Ardamax.rzx [Kaspersky Lab]
Keylog-Ardamax.dll [McAfee]
Trojan-Spy.Win32.Ardamax [Ikarus]
Win-Trojan/Ardamax.616960 [AhnLab]
8 [file and pathname of the sample #1] 846,107 bytes MD5: 0x038920828F1D1985C59625B0C65B0E1D
SHA-1: 0x63954129928EF40A6C1F01E1743688A49220510D
Application.Ardamax_Keylogger [PCTools]
Suspicious.MH690 [Symantec]
Trojan-Spy.Win32.Ardamax.cko [Kaspersky Lab]
Spy-Agent.cv [McAfee]
TSPY_ARDAMAX.HR [Trend Micro]
TrojanSpy:Win32/Ardamax.BB [Microsoft]
Trojan-Spy.Win32.Ardamax [Ikarus]
Dropper/Downloader.817294 [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
QERN.exe%System%\28463\QERN.exe962,560 bytes

Process NameMain Module Size
QERN.exe962,560 bytes

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.