Malware

Win32/KeyLogger.Ardamax.NBP (file analysis)

Malware Removal

The Win32/KeyLogger.Ardamax.NBP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/KeyLogger.Ardamax.NBP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Argentina)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/KeyLogger.Ardamax.NBP?


File Info:

crc32: F6F30B76
md5: 90476eabc66a23ac0dd7505d24fdcab1
name: 90476EABC66A23AC0DD7505D24FDCAB1.mlw
sha1: febe38eef3195b74063f1e9e5d9b6c4136cedd69
sha256: ea1594b13fb949fce549b6234e98f415ba3b1a69552c64dc6e8b15470065b6ee
sha512: b35d529f3ed567b69c89d704b07407cd570dbc5213d95f6cba1b9f0ce07e2f394897ea8f0f9792d54e03b0b45423600ee566dcfc63082bede0db22dac3df3cdc
ssdeep: 49152:eh8PQZnkpr5CTl45lDdoP1n5OZ2wenApnvMN645OGX8tBPWiZsm0145:E8Pp1GlqDdk1naYAvMM4pMx5UE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/KeyLogger.Ardamax.NBP also known as:

BkavW32.AIDetect.malware2
K7AntiVirusPassword-Stealer ( 003d8eec1 )
Elasticmalicious (high confidence)
DrWebTrojan.KeyLogger.28616
CynetMalicious (score: 100)
CAT-QuickHealMonitoringtool.Arda.21623
ALYacGen:Variant.Application.Keylogger.32
CylanceUnsafe
SangforPUP.Win32.Ardamax.NBP
AlibabaRiskWare:Win32/Convagent.9288c355
K7GWPassword-Stealer ( 003d8eec1 )
Cybereasonmalicious.bc66a2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KeyLogger.Ardamax.NBP
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
ClamAVWin.Keylogger.Ardamax-9809034-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Generic
BitDefenderGen:Variant.Application.Keylogger.32
NANO-AntivirusRiskware.Win32.KeyLogger.ezqndl
MicroWorld-eScanGen:Variant.Application.Keylogger.32
TencentWin32.Risk.Keylogger.Hqbf
Ad-AwareGen:Variant.Application.Keylogger.32
SophosGeneric PUA PO (PUA)
ComodoTrojWare.Win32.KeyLogger.Ardamax.K@6yxti1
BitDefenderThetaGen:NN.ZexaF.34294.OsW@aGTMBXCS
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ARDAMAX.SMN
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGeneric.mg.90476eabc66a23ac
EmsisoftGen:Variant.Application.Keylogger.32 (B)
SentinelOneStatic AI – Malicious PE
AviraSPR/Tool.Monitor.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2549DAD
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Application.Keylogger.32
SUPERAntiSpywareHack.Tool/Gen-KeyLogger
GDataGen:Variant.Application.Keylogger.32
AhnLab-V3Unwanted/Win32.Monitor.R230849
McAfeePUP-XQS-FR
MAXmalware (ai score=99)
VBA32BScope.Trojan.Keyloggerger
MalwarebytesRiskWare.ArdamaxKeyLogger
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_ARDAMAX.SMN
RisingTrojan.Generic@ML.100 (RDML:OQtj1ZCYfiPkDW9mUL1OIA)
YandexTrojan.GenAsa!UpdNYq/n1KA
IkarusPUA.Keylogger.Ardamax
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Generic
AVGWin32:KeyloggerX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/KeyLogger.Ardamax.NBP?

Win32/KeyLogger.Ardamax.NBP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment