Malware

MemScan:Application.Keylog.Ardamax.DLS removal tips

Malware Removal

The MemScan:Application.Keylog.Ardamax.DLS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Application.Keylog.Ardamax.DLS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine MemScan:Application.Keylog.Ardamax.DLS?


File Info:

name: EB9E76CE73187384507F.mlw
path: /opt/CAPEv2/storage/binaries/3bc1eacc1a9c65d1a876503cf796d93a0bf72acdd7c514db3c017b34b1bb6b43
crc32: 19539E7B
md5: eb9e76ce73187384507f076a7892bb79
sha1: c4dee459ef95b75d3338ef5de17df0f4c031d869
sha256: 3bc1eacc1a9c65d1a876503cf796d93a0bf72acdd7c514db3c017b34b1bb6b43
sha512: 04e9dada33c5324ff942cc82729de1847b0f129f4e690f241db3a5b09ee1d2cc70980a11685052100e3617ad4050a035a433a25dd8f01de553a036c85ae4f403
ssdeep: 12288:JrWLayfJ9fd76616z+qUDbkVWNqoP0ndJbQ1GAC4RUNWCywPcOX5ur:ZofdN1FqF0NXPOJbIGZ4RUN5pur
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18415333638CBE1B6EA760074677ED632CAFC7B75C346488B1797CB2A7890380D75A065
sha3_384: 2e2cb4072c306d0bfb2667ca337a63493e3ce4638c0fddc8fce358eabf2f045637f9d90fa801a7c6b356f8d7ffaf25a1
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-05-03 14:08:42

Version Info:

0: [No Data]

MemScan:Application.Keylog.Ardamax.DLS also known as:

BkavW32.Common.D9AB4195
LionicTrojan.Win32.Ardamax.l!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop1.4392
MicroWorld-eScanMemScan:Application.Keylog.Ardamax.DLS
ClamAVWin.Spyware.63231-2
FireEyeMemScan:Application.Keylog.Ardamax.DLS
CAT-QuickHealTrojan.MauvaiseRI.S5242891
SkyhighKeylog-Ardamax.cf
ALYacMemScan:Application.Keylog.Ardamax.DLS
Cylanceunsafe
ZillyaTrojan.Ardamax.Win32.107
SangforSpyware.Win32.Ardamax.V1a1
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ardamax.eca96127
K7GWPassword-Stealer ( 004c7ba21 )
K7AntiVirusPassword-Stealer ( 004c7ba21 )
ArcabitApplication.Keylog.Ardamax.DLS [many]
BitDefenderThetaGen:NN.ZexaF.36744.OyWaaSbXmG6O
VirITTrojan.Win32.Ardamax.E
SymantecSpyware.Ardakey
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Ardamax.cko
BitDefenderMemScan:Application.Keylog.Ardamax.DLS
NANO-AntivirusTrojan.Win32.Ardamax.baebj
SUPERAntiSpywareHack.Tool/Gen-KeyLogger
AvastWin32:Dropper-CER [Trj]
TencentWin32.Trojan.Generic.Ogil
EmsisoftMemScan:Application.Keylog.Ardamax.DLS (B)
F-SecureAdware.ADSPY/Dropper.Ardamax.Gen
VIPREMemScan:Application.Keylog.Ardamax.DLS
TrendMicroSPYW_ARDAKEY
SophosArdamax (PUA)
JiangminMonitor.Ardamax.fr
WebrootSystem.Monitor.Ardamax.Keylogge
GoogleDetected
AviraADSPY/Dropper.Ardamax.Gen
Antiy-AVLRiskWare[Monitor]/Win32.Ardamax
KingsoftWin32.Troj.Undef.a
XcitiumMalware@#s2pj2lhdylru
MicrosoftMonitoringTool:Win32/Ardamax
ViRobotTrojan.Win32.Ardamax.883731
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.34259929
VaristW32/Trojan.BWPC-7768
AhnLab-V3Trojan/Win32.Ardamax.R34335
McAfeeArtemis!EB9E76CE7318
MAXmalware (ai score=100)
VBA32Trojan.Genome.ai
MalwarebytesPUP.Optional.ArdamaxKeyLogger
PandaTrj/Dropper.JUP
TrendMicro-HouseCallSPYW_ARDAKEY
RisingMalware.Ardamax!8.E9D0 (TFE:5:ywDkJA0KzuN)
YandexTrojan.GenAsa!bFpSfCibAjw
IkarusTrojan-Spy.Win32.Ardamax
FortinetW32/Ardamax!tr.klog
AVGWin32:Dropper-CER [Trj]

How to remove MemScan:Application.Keylog.Ardamax.DLS?

MemScan:Application.Keylog.Ardamax.DLS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment