9b1569de016fbd9ae313976cf81f6839_0.npb

The file 9b1569de016fbd9ae313976cf81f6839_0.npb has been detected as a potentially unwanted program by 34 anti-malware scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
MD5:
9b1569de016fbd9ae313976cf81f6839

SHA-1:
fbed603cbb671a75ce4e540e58823dbca057af36

SHA-256:
6a35f9e0022ec90624e7401bf3bc5767bb2dea91a5f498e7eb552713b5a18f7a

Scanner detections:
34 / 68

Status:
Potentially unwanted

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/24/2024 3:12:33 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
TrojanSpy.Ardamax.WQ
7.1.1

AhnLab V3 Security
Win-Trojan/Xema.variant
2013.11.22

Avira AntiVirus
TR/Spy.Ardamax.J
7.11.115.18

avast!
Win32:Ardamax-PF [Spy]
2014.9-150125

AVG
Ardamax
2016.0.3219

Baidu Antivirus
AdWare.Win32.KeyLogger
4.0.3.15125

Bitdefender
Application.Ardamax.Keylogger.F
1.0.20.125

Bkav FE
W32.AdramaxB.Trojan
1.3.0.4562

Clam AntiVirus
Trojan.Spy-73362
0.98/18155

Comodo Security
ApplicUnsaf.Win32.Monitor.Ardamax.~A
17313

Emsisoft Anti-Malware
Application.Ardamax.Keylogger
8.15.01.25.01

ESET NOD32
Win32/KeyLogger.Ardamax
9.9080

Fortinet FortiGate
W32/Ardamax
1/25/2015

F-Prot
W32/Ardamax.J
v6.4.7.1.166

F-Secure
Monitoring-Tool:W32/Ardamax.AI
11.2015-25-01_1

G Data
Application.Ardamax.Keylogger
15.1.22

IKARUS anti.virus
Trojan-Spy.Ardamax.J
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10272

Kaspersky
not-a-virus:Monitor.Win32.Ardamax
14.0.0.2590

Malwarebytes
PUP.KeyLogger.Ardamax
v2015.01.25.01

McAfee
Keylog-Ardamax
5600.6875

Microsoft Security Essentials
MonitoringTool:Win32/Ardamax
1.163.1557.0

MicroWorld eScan
Application.Ardamax.Keylogger.F
16.0.0.75

NANO AntiVirus
Trojan.Win32.Ardamaxer.tbrs
0.28.0.56316

Norman
Obfuscated.C2!genr
11.20150125

Panda Antivirus
Trj/Agent.MIZ
15.01.25.01

Rising Antivirus
Trojan.Spy.Win32.Ardamax.dlm
23.00.65.15123

Sophos
Ardamax
4.95

Total Defense
Win32/Armax.G
37.0.10498

Trend Micro House Call
GRAY_Gen.0X1412S
7.2.25

Trend Micro
GRAY_Gen.0X1412S
10.465.25

Vba32 AntiVirus
TrojanSpy.Ardamaxer
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
23608

ViRobot
Trojan.Win32.Ardamaxer.705536
2011.4.7.4223

File size:
513 KB (525,312 bytes)

Common path:
C:\ProgramData\application data\net protector\npbkpn\9b1569de016fbd9ae313976cf81f6839_0.npb

File PE Metadata
Compilation timestamp:
1/14/2008 2:01:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:okIahY1erZBfqalnScbMpmiYTEhkr6km7iADo/+V0NM/CAfr:oqY1er/nScw/uekrtAXj

Entry address:
0x2A946

Entry point:
E8, 21, 69, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 38, B0, 46, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 3C, B0, 46, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, A5, 25, 00, 00, 85, C0, 75, 06, B8, A0, B1, 46, 00, C3, 83, C0, 08, C3, E8, 92, 25, 00, 00, 85, C0, 75, 06, B8, A4, B1, 46, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Entropy:
6.4698

Code size:
365 KB (373,760 bytes)

Remove 9b1569de016fbd9ae313976cf81f6839_0.npb - Powered by Reason Core Security