Malware

Application.RemoteAdmin.RIQ malicious file

Malware Removal

The Application.RemoteAdmin.RIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.RemoteAdmin.RIQ virus can do?

  • Presents an Authenticode digital signature
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

How to determine Application.RemoteAdmin.RIQ?


File Info:

crc32: 263E07D8
md5: 0e4b2e7cb031c33a99ad7b9bf8193170
name: AmmyAdmin.exe
sha1: 7561777ec0a54cfcffda94395698f992ba9c20c8
sha256: 9bdb57a113e87e726d44938e64cd103d17f1302f93973aae140026aedfdea39f
sha512: 0e2867c20c1a713c8508ce07348c700b57c45e7363635fe43901f965e56b382a4d4bf9f7ee56b702da3ea73b260fdd872202c3f0407ce77607b341604900dda9
ssdeep: 12288:+c0dZib4t9uOroAgUHvCUt4RtlTc+YNKpQsNvVvYg4:+c/UtwOrZgUHv54Rt6+YNkQs/94
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

Application.RemoteAdmin.RIQ also known as:

MicroWorld-eScanApplication.RemoteAdmin.RIQ
FireEyeGeneric.mg.0e4b2e7cb031c33a
CAT-QuickHealTrojan.GenericPMF.S181297
McAfeeRemAdm-Ammyy
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004b90511 )
BitDefenderApplication.RemoteAdmin.RIQ
K7GWUnwanted-Program ( 004b90511 )
Cybereasonmalicious.cb031c
Invinceaheuristic
F-ProtW32/RemoteAdmin.C.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:RemoteAdmin-K [Tool]
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
AlibabaRiskWare:Win32/Ammyy.379f626b
NANO-AntivirusRiskware.Win32.RemoteAdmin.egaxvy
Endgamemalicious (high confidence)
ComodoApplication.Win32.RemoteAdmin.Ammyy.CA@6lncg7
DrWebProgram.RemoteAdmin.863
McAfee-GW-EditionRemAdm-Ammyy
Trapminemalicious.high.ml.score
EmsisoftApplication.RemoteAdmin.RIQ (B)
CyrenW32/RemoteAdmin.C.gen!Eldorado
JiangminRemoteAdmin.Ammyy.eb
WebrootW32.Ammyy.Ra
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy.aqm
ArcabitApplication.RemoteAdmin.RIQ
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
AhnLab-V3Unwanted/Win32.RemoteAdmin.R218311
Acronissuspicious
MAXmalware (ai score=76)
Ad-AwareApplication.RemoteAdmin.RIQ
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoDi/CRxG2m8HX/taYN74rs)
YandexRiskware.RemoteAdmin!
SentinelOneDFI – Malicious PE
eGambitRAT.Ammyy
AVGFileRepMalware [PUP]
MaxSecureVirus.Trojan.Ammyy.wrj

How to remove Application.RemoteAdmin.RIQ?

Application.RemoteAdmin.RIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment