Ardamax Keylogger 2.8

Ardamax Keylogger 2.8 is a keylogger that runs in hidden mode. It also captures the user’s activity.

General information:

Malware Name:Ardamax Keylogger 2.8
Malware Type:Keylogger
Company Name:Ardamax Software
Company URL:http://ardamax.com/
Threat Level:Severe Risk
Operating System:WIN XP
Installation Type:Installed through EXE
Operation:Time of After Installation

Company Description:

Ardamax Software provides you the software Ardamax Keylogger 2.8 that is a simple keylogger program captures user’s activity and saves it to a text or HTML logfile. In addition, you can choose to have the log file sent by email (every X minutes) to an email address you specify. The program can run in a hidden mode, which completely hides it from the TaskManager, Programs menu etc. or with an optional tray icon.

Spyware Description:

Ardamax Keylogger 2.8 is a keylogger that runs in hidden mode. It also captures the user’s activity.

Characteristics/Symptoms:

    -> It runs in hidden mode. -> It also captures the user’s activity.

Additional information might be found here:

googleSearch at Google for Ardamax Keylogger 2.8
bingSearch at Bing for Ardamax Keylogger 2.8
yahooSearch at Yahoo for Ardamax Keylogger 2.8

Processes Running:

HTV.exe

File information Created after Installation:

File LocationSize (Bytes)Type
C:\Documents and Settings\All Users\Start Menu\Programs\Ardamax Keylogger\Log Viewer.lnk542Shortcut
C:\Program Files\HTV\AKV.exe402944Application
C:\Program Files\HTV\HTV.0021084002 File

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\Ardamax Keylogge

Registry information Created after Installation:

Main Registry KeySub Registry KeyKey Value Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ardamax KeyloggerSlowInfoCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ardamax Keylogger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ardamax KeyloggerDisplayName