Malware

Application.RemoteAdmin.RIQ (B) malicious file

Malware Removal

The Application.RemoteAdmin.RIQ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.RemoteAdmin.RIQ (B) virus can do?

  • Starts servers listening on 0.0.0.0:5931
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
aa.admin66.info
am.admin66.info
a.tomx.xyz

How to determine Application.RemoteAdmin.RIQ (B)?


File Info:

crc32: 2172212F
md5: 34af063bf81e7876fb24466257dce228
name: aa.exe
sha1: 368454032849c09b7ef84d9eba4bfe0575a0d93b
sha256: 522463402e0a2a486737a929bae12bfa8319bf1894575d65cad9680750ab9d9a
sha512: b45dbf6404a059f5a377d7953dd290e7e590e0a4b3e01a40c7fe46ed593a5c740e057ce7845d18f33e8134f97c1488c061d92583e98ff0f1edd5fce8a0d32660
ssdeep: 12288:pc0dZib4t9uOroAgUHvCUt4RtlTc+YNKpQsNvVL9g0:pc/UtwOrZgUHv54Rt6+YNkQs7+0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

Application.RemoteAdmin.RIQ (B) also known as:

MicroWorld-eScanApplication.RemoteAdmin.RIQ
FireEyeGeneric.mg.34af063bf81e7876
CAT-QuickHealTrojan.GenericPMF.S181297
McAfeeRemAdm-Ammyy
CylanceUnsafe
VIPRERemote-Access.Win32.Ammyy (not malicious)
K7AntiVirusUnwanted-Program ( 004b90511 )
BitDefenderApplication.RemoteAdmin.RIQ
K7GWUnwanted-Program ( 004b90511 )
CrowdStrikewin/malicious_confidence_100% (D)
F-ProtW32/RemoteAdmin.C.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:RemoteAdmin-K [Tool]
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
AlibabaRiskWare:Win32/Ammyy.dc7d2753
NANO-AntivirusRiskware.Win32.RemoteAdmin.egaxvy
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazr8I/duU4I0hCPqCO8/WfHn)
Endgamemalicious (high confidence)
EmsisoftApplication.RemoteAdmin.RIQ (B)
ComodoApplication.Win32.RemoteAdmin.Ammyy.CA@6lncg7
DrWebProgram.RemoteAdmin.863
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.RemAdmAmmyy.bh
Trapminemalicious.high.ml.score
CyrenW32/RemoteAdmin.C.gen!Eldorado
JiangminRemoteAdmin.Ammyy.eb
MaxSecureVirus.Trojan.Ammyy.wrj
WebrootW32.Ammyy.Ra
MAXmalware (ai score=100)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy.aqm
ArcabitApplication.RemoteAdmin.RIQ
SUPERAntiSpywarePUP.RemoteAdmin/Variant
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Unwanted/Win32.RemoteAdmin.R218311
Acronissuspicious
Ad-AwareApplication.RemoteAdmin.RIQ
MalwarebytesPUP.Optional.RAAmmyy
PandaTrj/CI.A
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
YandexRiskware.RemoteAdmin!
SentinelOneDFI – Malicious PE
eGambitRAT.Ammyy
FortinetRiskware/Generic_PUA_DG
BitDefenderThetaGen:NN.ZexaE.34110.Uq0@aifdeMgk
AVGWin32:RemoteAdmin-K [Tool]
Cybereasonmalicious.bf81e7
Paloaltogeneric.ml
Qihoo-360Win32/Virus.RemoteAdmin.fe6

How to remove Application.RemoteAdmin.RIQ (B)?

Application.RemoteAdmin.RIQ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment