Malware

What is “RemoteAdmin.Win32.Ammyy.aqm”?

Malware Removal

The RemoteAdmin.Win32.Ammyy.aqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Ammyy.aqm virus can do?

  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
rl.ammyy.com

How to determine RemoteAdmin.Win32.Ammyy.aqm?


File Info:

crc32: 29A750CC
md5: 1fc7c230d6db0d7a0da6f415da271159
name: ammyy.exe
sha1: e0bd10d83bc7b3f1eb628974a8f690ffda6e9351
sha256: 7a836e718b70f586695d1bced9eacfb1aa1b67387b051d0536669754b391fe81
sha512: 96d64cba5bf650066e54bcb84f13aabd1992811963ae2dd3530431e86bbc3230d673545953d35767fbf85f61d86b44170d61200d1ffb4f4945268bfc3a7b1403
ssdeep: 12288:Tc1dZibTD9uOroAgeHvCUt4RtlTc+YNKpQsNvVd1gF:Tcc/DwOrZgeHv54Rt6+YNkQsNmF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Ammyy.aqm also known as:

BkavW32.HfsAdware.3C2B
DrWebProgram.RemoteAdmin.863
MicroWorld-eScanApplication.RemoteAdmin.RIQ
FireEyeGeneric.mg.1fc7c230d6db0d7a
CAT-QuickHealTrojan.GenericPMF.S181297
McAfeeRemAdm-Ammyy
CylanceUnsafe
BitDefenderApplication.RemoteAdmin.RIQ
CrowdStrikewin/malicious_confidence_80% (D)
ArcabitApplication.RemoteAdmin.RIQ
Invinceaheuristic
CyrenW32/RemoteAdmin.C.gen!Eldorado
SymantecRemacc.Ammyy
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallPUA.Win32.AmmyyAdmin.AE
ClamAVWin.Malware.Agent247378318/CRDF-1
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
AlibabaRiskWare:Win32/Ammyy.eb003bfd
NANO-AntivirusRiskware.Win32.RemoteAdmin.egaxvy
AvastWin32:PUP-gen [PUP]
RisingMalware.Heuristic!ET#99% (CLOUD)
Ad-AwareApplication.RemoteAdmin.RIQ
EmsisoftApplication.RemoteAdmin.RIQ (B)
ComodoApplication.Win32.RemoteAdmin.Ammyy.CA@6lncg7
TrendMicroPUA.Win32.AmmyyAdmin.AE
McAfee-GW-EditionRemAdm-Ammyy
F-ProtW32/RemoteAdmin.C.gen!Eldorado
JiangminRemoteAdmin.Ammyy.eb
MaxSecureVirus.Trojan.Ammyy.wrj
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy.aqm
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.Agent.769528
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.aqm
AhnLab-V3Unwanted/Win32.RemoteAdmin.R218311
MAXmalware (ai score=99)
APEXMalicious
YandexTrojan.Igent.bTdyNW.4
SentinelOneDFI – Malicious PE
eGambitRAT.Ammyy
GDataWin32.Riskware.RemoteAdmin.A
WebrootW32.Ammyy.Ra
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.0d6db0

How to remove RemoteAdmin.Win32.Ammyy.aqm?

RemoteAdmin.Win32.Ammyy.aqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment