Malware

MonitoringTool:Win32/Ardamax malicious file

Malware Removal

The MonitoringTool:Win32/Ardamax is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MonitoringTool:Win32/Ardamax virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MonitoringTool:Win32/Ardamax?


File Info:

crc32: 2E3EA990
md5: ced1dd7f32a91e2f28546cb5dac8cdfc
name: CED1DD7F32A91E2F28546CB5DAC8CDFC.mlw
sha1: f3a467e8229d6b72fa8a49d3cd0c18c8dfaf579e
sha256: 037643bdc4b7e49a119f1027ef62f1cd5472fd2586714186b5ce423119dab995
sha512: ac7322b8cf828fd60fab244f9b1ccb2b480e453b431d7c2bb47d0cb6de82b9ea6d33711c9e1c5c96f6f49b0c6bffabb2e0317136241b5a99e982c14158ebbdb0
ssdeep: 49152:v59y8otX0YvQZ1Sc2+R/xzGNca6BTVJKI+Pk:R9y8oyYvQZGAoNd6BTVJKIF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MonitoringTool:Win32/Ardamax also known as:

BkavW32.AIDetect.malware1
K7AntiVirusPassword-Stealer ( 004c16741 )
Elasticmalicious (high confidence)
DrWebTrojan.KeyLogger.15755
CynetMalicious (score: 100)
CAT-QuickHealMonitoringTool.Ardamax.A5
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Limital.88726530
K7GWPassword-Stealer ( 004c16741 )
Cybereasonmalicious.f32a91
CyrenW32/Gbot.A.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/KeyLogger.Ardamax.NBG
APEXMalicious
AvastWin32:Ardamax-RM [PUP]
Kasperskynot-a-virus:HEUR:Monitor.Win32.Ardamax.gen
BitDefenderGen:Variant.FAkeAlert.105
NANO-AntivirusTrojan.Win32.KeyLogger.ccidab
ViRobotBackdoor.Win32.A.Gbot.1912832
MicroWorld-eScanGen:Variant.FAkeAlert.105
TencentMalware.Win32.Gencirc.10b6e0ce
Ad-AwareGen:Variant.FAkeAlert.105
SophosMal/Generic-R + Troj/Zbot-DNE
ComodoApplication.Win32.Ardamax.NBX@7hiiv4
BitDefenderThetaGen:NN.ZexaF.34294.5vW@a8dY6kf
VIPRETrojan.Win32.Gbot.aakv (v)
TrendMicroTSPY_ARDAMAX.SM1
McAfee-GW-EditionBehavesLike.Win32.FilePatcher.tc
FireEyeGeneric.mg.ced1dd7f32a91e2f
EmsisoftGen:Variant.FAkeAlert.105 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.anjqp
AviraTR/Taranis.3013
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.F14D2
KingsoftHeur.SSC.2678493.1216.(kcloud)
MicrosoftMonitoringTool:Win32/Ardamax
SUPERAntiSpywareHack.Tool/Gen-KeyLogger
GDataGen:Variant.FAkeAlert.105
Acronissuspicious
McAfeeKeylog-FAQ
MAXmalware (ai score=96)
VBA32BScope.Trojan.Keyloggerger
MalwarebytesTrojan.FakeAV
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ARDAMAX.SM1
RisingTrojan.Generic@ML.100 (RDML:lPE3qJ2pSFAeWSHRmtmr0A)
YandexTrojan.GenAsa!EDm1H6/DQlU
Ikarusnot-a-virus:Monitor.Win32.Ardamax
MaxSecureTrojan.Malware.12280086.susgen
FortinetW32/Gbot.ACCR!tr.bdr
AVGWin32:Ardamax-RM [PUP]
Paloaltogeneric.ml

How to remove MonitoringTool:Win32/Ardamax?

MonitoringTool:Win32/Ardamax removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment