Categories: PUA

Should I remove “PUP.Optional.RAAmmyy”?

The PUP.Optional.RAAmmyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.RAAmmyy virus can do?

  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
rl.ammyy.com
a.tomx.xyz

How to determine PUP.Optional.RAAmmyy?


File Info:

crc32: E1F83A5Fmd5: eb8c6abfc9b3def84f666ae731a8e908name: ammy35.exesha1: b3c71b8070f9c2300f2c462ec14b49c413c57a65sha256: 61f8a98198d6777c4e7fa54d0a6b898944e0500e0ce4c7cf5732d16707f70d3asha512: 613da33a36a2d0f77eed0d6e006ceb9ab8e90724d742fb4e0fb51051cefcb39c36c19d546fc340b1d51a03d2d528d8dab9fc3349baf3d71d17d165fa25adb723ssdeep: 12288:pii1SQxjP6j34G+t2aPHXuTy4RtfUwFDZAQmsNs8wigvP/:h1S6z6j34G+t2afXh4RtxFD/mAsVfvtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: InternalName: Ammyy AdminFileVersion: 3.5CompanyName: Ammyy LLCPrivateBuild: LegalTrademarks: Comments: ProductName: Ammyy AdminSpecialBuild: ProductVersion: 3.5FileDescription: Ammyy AdminOriginalFilename: Translation: 0x0409 0x04b0

PUP.Optional.RAAmmyy also known as:

MicroWorld-eScan Gen:Variant.Application.RemoteAdmin.6
FireEye Generic.mg.eb8c6abfc9b3def8
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
BitDefender Gen:Variant.Application.RemoteAdmin.6
K7GW Unwanted-Program ( 004b889d1 )
K7AntiVirus Unwanted-Program ( 004b889d1 )
Arcabit Trojan.Application.RemoteAdmin.6
TrendMicro TROJ_GEN.R014C0ODI19
NANO-Antivirus Riskware.Win32.RemoteAdmin.deqhmm
F-Prot W32/RemoteAdmin.C.gen!Eldorado
Symantec SMG.Heur!gen
APEX Malicious
Paloalto generic.ml
Kaspersky not-a-virus:HEUR:RemoteAdmin.Win32.Generic
Alibaba RemoteAdmin:Win32/Ammyy.2c894e4e
Rising Malware.Heuristic.MLite(93%) (AI-LITE:d8c+MsDkXAoBl/yzKHxZvA)
Ad-Aware Gen:Variant.Application.RemoteAdmin.6
Emsisoft Gen:Variant.Application.RemoteAdmin.6 (B)
Comodo Application.Win32.RemoteAdmin.Ammyy.CA@6lncg7
DrWeb Program.RemoteAdmin.701
Zillya Adware.BrowseFox.Win32.423705
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.RemAdmAmmyy.bh
Fortinet Riskware/Ammyy
Trapmine malicious.high.ml.score
Cyren W32/RemoteAdmin.C.gen!Eldorado
Jiangmin RemoteAdmin.Generic.a
Webroot W32.Trojan.Ra
MAX malware (ai score=99)
Antiy-AVL RiskWare[RemoteAdmin]/Win32.Ammyy
Endgame malicious (high confidence)
Microsoft Program:Win32/Bitrepeyu.C
ZoneAlarm not-a-virus:HEUR:RemoteAdmin.Win32.Generic
AhnLab-V3 Unwanted/Win32.RemoteAdmin.R218311
Acronis suspicious
McAfee RemAdm-Ammyy
Malwarebytes PUP.Optional.RAAmmyy
Panda Trj/Chgt.F
ESET-NOD32 a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCall TROJ_GEN.R014C0ODI19
Yandex Riskware.RemoteAdmin!
SentinelOne DFI – Malicious PE
eGambit RAT.Ammyy
GData Win32.Riskware.RemoteAdmin.A
AVG FileRepMetagen [Malware]
Cybereason malicious.fc9b3d
Avast Win32:RemoteAdmin-K [Tool]
CrowdStrike win/malicious_confidence_90% (D)
Qihoo-360 Win32/Application.RemoteAdmin.1b9

How to remove PUP.Optional.RAAmmyy?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Fragtor.545276”?

The Fragtor.545276 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.4236857157 removal tips

The Malware.AI.4236857157 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

How to remove “Win32/AutoRun.VB.ALG”?

The Win32/AutoRun.VB.ALG is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/Spy.Virkonni.F removal instruction

The Win32/Spy.Virkonni.F is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Backdoor.Farfli.AH”?

The Backdoor.Farfli.AH is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Packed.Win32.Klone.ao removal

The Packed.Win32.Klone.ao is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago