Malware

What is “MemScan:Application.Keylog.Ardamax.DMA”?

Malware Removal

The MemScan:Application.Keylog.Ardamax.DMA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Application.Keylog.Ardamax.DMA virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine MemScan:Application.Keylog.Ardamax.DMA?


File Info:

name: D30A5EDB4CBE5907CADE.mlw
path: /opt/CAPEv2/storage/binaries/210103f71113a915452b331611a096a727090567da8fdda154c44369b298b760
crc32: 4748A2D9
md5: d30a5edb4cbe5907cade16cedc63beff
sha1: 8e1f464c25ba993ad24b0610f227f40a8beec1fa
sha256: 210103f71113a915452b331611a096a727090567da8fdda154c44369b298b760
sha512: b808b5b46ed43c0ecf31a1201e37aa7c461ac08f24c3041164fa840f4769cf6addfbc7dc73ff148a304fda05c1228bb0370aa2f6b76221578f51bc4a81186248
ssdeep: 24576:l64MVTbn99wNHPSGvZ5ExhOLF0fHwKp/vwiujsE:l64MTbnePZXEOLsVPos
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A4533563B160336DCF78B794D6F8B389F3CB43312A2A01B15CFC69A2B566E440552EE
sha3_384: 97a98aeb3e35e5dd77433cba83b439f867e5133b12af9f536ffaa3b605d421b0e4eeca40c339d816e77b4f6bc064ed28
ep_bytes: e8b8220000e979feffff8bff558bec81
timestamp: 2011-05-16 10:31:08

Version Info:

0: [No Data]

MemScan:Application.Keylog.Ardamax.DMA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ardamax.lmIa
MicroWorld-eScanMemScan:Application.Keylog.Ardamax.DMA
ClamAVWin.Trojan.Agent-313898
FireEyeGeneric.mg.d30a5edb4cbe5907
CAT-QuickHealTrojan.Ardamax.A
McAfeeKeylog-Ardamax.cg
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Ardamax.Win32.5383
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0030898f1 )
AlibabaRiskWare:Win32/ArchSMS.ebecc610
K7GWPassword-Stealer ( 0030898f1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36744.lvW@aSG98bWT
VirITTrojan.Win32.SHeur3.BZWO
SymantecTrojan.Malcol
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/KeyLogger.Ardamax.NAZ
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Monitor.Win32.Ardamax.ccs
BitDefenderMemScan:Application.Keylog.Ardamax.DMA
NANO-AntivirusTrojan.Win32.Drop.xfpnf
RisingTrojan.Win32.Akvexe.a (CLASSIC)
SophosArdamax (PUA)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.MulDrop2.59534
VIPREMemScan:Application.Keylog.Ardamax.DMA
TrendMicroTROJ_GEN.R002C0OBB24
Trapminemalicious.high.ml.score
EmsisoftMemScan:Application.Keylog.Ardamax.DMA (B)
IkarusIM-Worm.Win32.VB
JiangminTrojanSpy.Ardamax.bng
WebrootSystem.Monitor.Ardamax.Keylogge
GoogleDetected
AviraTR/Spy.Gen
Antiy-AVLTrojan[Spy]/Win32.Ardamax
XcitiumMalware@#edj9ot0k7d7u
ArcabitApplication.Keylog.Ardamax.DMA
ViRobotTrojan.Win32.A.Ardamax.1223680
ZoneAlarmnot-a-virus:Monitor.Win32.Ardamax.ccs
GDataMemScan:Application.Keylog.Ardamax.DMA
VaristW32/Ardamax.F_a.gen!Eldorado
AhnLab-V3Trojan/Win32.Ardamax.R6533
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Xbot
ALYacMemScan:Application.Keylog.Ardamax.DMA
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0OBB24
TencentMalware.Win32.Gencirc.10b33840
SentinelOneStatic AI – Malicious PE
MaxSecureHoax.ArchSMS.loaf
FortinetW32/Dropper.AAAE!tr
AVGWin32:KeyloggerX-gen [Trj]
AvastWin32:KeyloggerX-gen [Trj]

How to remove MemScan:Application.Keylog.Ardamax.DMA?

MemScan:Application.Keylog.Ardamax.DMA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment