Quote:
Originally Posted by macarao
|
Scan Of The Executable:
This is a
W32/Ardamax too. A
Keylogger like the previous one, but slightly different. It runs silent in memory, it can't be noticed in the Taskmanager! The Hidden Process is polymorphic and can change its structure.
Quote:
Antivirus Version Last Update Result
AhnLab-V3 2008.10.2.0 2008.10.02 -
AntiVir 7.8.1.34 2008.10.02 ADSPY/Dropper.Ardamax.Gen
Authentium 5.1.0.4 2008.10.02 W32/Trojan2.CJYV
Avast 4.8.1248.0 2008.10.01 Win32:Agent-LWO
AVG 8.0.0.161 2008.10.02 PSW.Generic6.WIW
BitDefender 7.2 2008.10.02 Trojan.Generic.530730
CAT-QuickHeal 9.50 2008.10.01 -
ClamAV 0.93.1 2008.10.02 Trojan.Ardamax-305
DrWeb 4.44.0.09170 2008.10.02 -
eSafe 7.0.17.0 2008.10.01 -
eTrust-Vet 31.6.6121 2008.10.02 -
Ewido 4.0 2008.10.02 Logger.Ardamax.t
F-Prot 4.4.4.56 2008.10.02 W32/Trojan2.CJYV
F-Secure 8.0.14332.0 2008.10.02 Trojan-Spy.Win32.Ardamax.t
Fortinet 3.113.0.0 2008.10.02 -
GData 19 2008.10.02 Trojan.Generic.530730
Ikarus T3.1.1.34.0 2008.10.02 Trojan-Spy.Win32.Ardamax.t
K7AntiVirus 7.10.481 2008.10.02 Trojan-Spy.Win32.Ardamax.t
Kaspersky 7.0.0.125 2008.10.02 Trojan-Spy.Win32.Ardamax.t
McAfee 5396 2008.10.02 Spy-Agent.cv
Microsoft 1.4005 2008.10.02 TrojanSpy:Win32/Ardamax.D
NOD32 3489 2008.10.02 -
Norman 5.80.02 2008.10.02 W32/Ardamax.GCG
Panda 9.0.0.4 2008.10.02 -
PCTools 4.4.2.0 2008.10.02 -
Prevx1 V2 2008.10.02 Malicious Software
Rising 20.63.62.00 2008.09.28 Trojan.Spy.Win32.Ardamax.t
SecureWeb-Gateway 6.7.6 2008.10.02 Ad-Spyware.Dropper.Ardamax.Gen
Sophos 4.34.0 2008.10.02 Ardamax Installer
Sunbelt 3.1.1668.1 2008.09.24 -
Symantec 10 2008.10.02 -
TheHacker 6.3.0.9.098 2008.10.01 Trojan/Spy.Ardamax.t
TrendMicro 8.700.0.1004 2008.10.02 TSPY_ARDAMAX.HR
VBA32 3.12.8.6 2008.10.02 Trojan-Spy.Win32.Ardamax.t
ViRobot 2008.10.2.1403 2008.10.02 -
VirusBuster 4.5.11.0 2008.10.01 -
|
This is starting to be pathetic, releasing the same Keylogger, but slightly modified. Both were FAILS! :)