PUA

PUP.Optional.Ammyy malicious file

Malware Removal

The PUP.Optional.Ammyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Ammyy virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
rl.ammyy.com
a.tomx.xyz

How to determine PUP.Optional.Ammyy?


File Info:

crc32: DBEED055
md5: 121e1634bf18768802427f0a13f039a9
name: AA_v3.exe
sha1: 8868654ba10fb4c9a7bd882d1f947f4fd51e988e
sha256: 5fc600351bade74c2791fc526bca6bb606355cc65e5253f7f791254db58ee7fa
sha512: 393df326af3109fe701b579b73f42f7a9b155bb4df6ea7049ad3ae9fdd03446576b887a99eb7a0d59949a7a63367e223253448b6f1a0ebeaf358fa2873dcc200
ssdeep: 12288:hSX+EvrCA3FNIs34Zk1L1ZSNlm3Spsal6lbRtMuStGKcsCSqcl90Va1ugp:2FNN4Zk1LTclm3e1kbRtyGKcpHcl517p
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.9
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.9
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

PUP.Optional.Ammyy also known as:

BkavW32.HfsAdware.3C2B
MicroWorld-eScanGen:Variant.Application.RemoteAdmin.6
FireEyeGeneric.mg.121e1634bf187688
McAfeeRemAdm-Ammyy
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusHacktool ( 005519b11 )
BitDefenderGen:Variant.Application.RemoteAdmin.6
K7GWHacktool ( 005519b11 )
Cybereasonmalicious.4bf187
TrendMicroHackTool.Win32.AmmyyAdmin.AD
SymantecRemacc.Ammyy
APEXMalicious
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.yzv
AlibabaRiskWare:Win32/Ammyy.e87f682b
NANO-AntivirusTrojan.Win32.RemoteAdmin.fnziod
AegisLabRiskware.Win32.Ammyy.1!c
RisingMalware.Undefined!8.C (CLOUD)
Ad-AwareGen:Variant.Application.RemoteAdmin.6
EmsisoftGen:Variant.Application.RemoteAdmin.6 (B)
ComodoMalware@#1m8vr6ed8fz3f
F-SecurePrivacyRisk.SPR/Ammyy.A
DrWebProgram.RemoteAdmin.879
ZillyaTool.Ammyy.Win32.7
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.RemAdmAmmyy.bh
CyrenW32/Trojan.YYPM-4200
JiangminRemoteAdmin.Ammyy.fq
WebrootW32.Trojan.Ra
AviraSPR/Ammyy.A
MAXmalware (ai score=100)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy
Endgamemalicious (high confidence)
ArcabitTrojan.Application.RemoteAdmin.6
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.yzv
AhnLab-V3Unwanted/Win32.RemoteAdmin.R278120
MalwarebytesPUP.Optional.Ammyy
ZonerTrojan.Win32.78314
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallHackTool.Win32.AmmyyAdmin.AD
YandexTrojan.Igent.bRQHa9.4
SentinelOneDFI – Suspicious PE
eGambitRAT.Ammyy
FortinetRiskware/RemoteAdmin_Ammyy
AVGFileRepMalware [PUP]
AvastWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Adware.37e

How to remove PUP.Optional.Ammyy?

PUP.Optional.Ammyy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment