We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
TrojanSpy:Win32/Ardamax.BF
Aliases: Win-Trojan/Ardamax.14848.B (AhnLab) TR/Spy.Ardamax.cko (Avira) Trojan.DownLoad.1726 (Dr.Web) Trojan-Spy.Win32.Ardamax.e (Kaspersky) Keylog-Ardamax.dr.gen (McAfee) MonitoringTool:Win32/Ardamax (other) Trojan.Spy.Win32.Ardamax.e (Rising AV) Ardamax Installer (Sophos) TSPY_ARDAMAX.E (Trend Micro) Trojan.DR.Ardamax.Gen.3 (VirusBuster)
Summary
TrojanSpy:Win32/Ardamax.BF is a key logger that is configured to capture and save user activity to a log file. Win32/Ardamax could be configured by a malware author to send the log file to a specified address.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.