Malware

About “Application.RemoteAdmin.RIN” infection

Malware Removal

The Application.RemoteAdmin.RIN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.RemoteAdmin.RIN virus can do?

  • Presents an Authenticode digital signature
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
rl.ammyy.com
a.tomx.xyz

How to determine Application.RemoteAdmin.RIN?


File Info:

crc32: 69F4E921
md5: 11bc606269a161555431bacf37f7c1e4
name: AA_v3.exe
sha1: 63c52b0ac68ab7464e2cd777442a5807db9b5383
sha256: 1831806fc27d496f0f9dcfd8402724189deaeb5f8bcf0118f3d6484d0bdee9ed
sha512: 0be867fce920d493d2a37f996627bceea87621ba4071ae4383dd4a24748eedf7dc5ca6db089217b82ec38870248c6840f785683bf359d1014c7109e7d46dd90f
ssdeep: 12288:XVFUEuNmwvGrw9i0aTGRGicBckyyFRtWY1i3FTsvOVV0gz:3UEUUw9RaTNicBrPFRtJ1iVTsC5z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

Application.RemoteAdmin.RIN also known as:

BkavW32.HfsAdware.3C2B
DrWebProgram.RemoteAdmin.875
MicroWorld-eScanApplication.RemoteAdmin.RIN
FireEyeGeneric.mg.11bc606269a16155
CAT-QuickHealTrojan.Agent
ALYacMisc.HackTool.RemoteAdmin.Ammyy
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderApplication.RemoteAdmin.RIN
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.269a16
TrendMicroHKTL_AMMYYADMN
F-ProtW32/RemoteAdmin.Ammyy
SymantecRemacc.Ammyy
APEXMalicious
ClamAVWin.Malware.Agent-6342069-0
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.xmr
AlibabaRiskWare:Win32/Ammyy.5cf51771
NANO-AntivirusRiskware.Win32.AmmyAdmin.dskdxp
RisingMalware.Heuristic!ET#92% (CLOUD)
Ad-AwareApplication.RemoteAdmin.RIN
ComodoApplicUnsaf@#29xqcxr9iprzw
Invinceaheuristic
McAfee-GW-EditionRemAdm-Ammyy
CyrenW32/RemoteAdmin.ACSY-7276
JiangminRemoteAdmin.Ammyy.bm
eGambitRAT.Ammyy
MAXmalware (ai score=100)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.xmr
AhnLab-V3Unwanted/Win32.RemoteAdmin.R153011
McAfeeRemAdm-Ammyy
TACHYONAbuse-Worry/W32.Ammyy.773624
ZonerTrojan.Win32.39604
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallHKTL_AMMYYADMN
YandexTrojan.Igent.bTfJOh.6
SentinelOneDFI – Malicious PE
WebrootW32.Ammyy.Ra
AVGFileRepMalware [PUP]
AvastWin32:RemoteAdmin-K [Tool]
Qihoo-360Win32/Trojan.Adware.37e

How to remove Application.RemoteAdmin.RIN?

Application.RemoteAdmin.RIN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment