Malware

About “RemoteAdmin.Win32.Ammyy.cj” infection

Malware Removal

The RemoteAdmin.Win32.Ammyy.cj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Ammyy.cj virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:5931
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

rl.ammyy.com
www.ammyy.com

How to determine RemoteAdmin.Win32.Ammyy.cj?


File Info:

crc32: 232EC7F3
md5: a2d7d62d6aa274bb9421488bba647835
name: AMMYY_Admin.exe
sha1: 114752dd789ed206b0325c0b143090c0026747fe
sha256: 26930c6ad468c5b87a720ca949ae7f97c3fe0664688f7bd19224ec5d46020c47
sha512: 0c889dcb647ec60f56621a31d131dc936c9d30fe24e00451e6f09e809f9ea9c457bcf34d9ef85a55a22e4fdf271e841462cd5afee2bd940890f2f034bc3dfdec
ssdeep: 12288:caAXOKLSwaIN5U8xvFoRQMEoO2rx8ikfRtjIe9rtv8zl6mi/gQ:AeK+waI8JRQMEJ2rufRtse9rtv8zlBi3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Ammyy Admin
FileVersion: 2.12
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 2.12
FileDescription: Ammyy Admin
OriginalFilename: AMMYY_Admin.exe
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Ammyy.cj also known as:

BkavW32.HfsAdware.5214
FireEyeGeneric.mg.a2d7d62d6aa274bb
McAfeeRDN/RemAdm-Generic
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 004b90511 )
K7GWUnwanted-Program ( 004b90511 )
TrendMicroTROJ_GEN.R002C0OKG19
SymantecRemacc.Ammyy
APEXMalicious
AvastWin32:PUP-gen [PUP]
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.cj
AlibabaRiskWare:Win32/Ammyy.12965610
NANO-AntivirusRiskware.Win32.Ammyy.ddfrgh
ViRobotAdware.Ammyy.667344
AegisLabRiskware.Win32.Ammyy.1!c
RisingMalware.Undefined!8.C (CLOUD)
Endgamemalicious (high confidence)
SophosGeneric PUA BB (PUA)
DrWebProgram.Ammyy.1
Invinceaheuristic
McAfee-GW-EditionRDN/RemAdm-Generic
Trapminemalicious.high.ml.score
JiangminRemoteAdmin.Agent.a
WebrootW32.Ammyy.Ra
MAXmalware (ai score=99)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy.cj
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.cj
MicrosoftPUA:Win32/Bitrepeyp.C
AhnLab-V3Win-AppCare/Remoteaammyy.667344
Acronissuspicious
VBA32TrojanDownloader.Agent
MalwarebytesRiskWare.RemoteAdmin
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OKG19
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
AVGWin32:PUP-gen [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Virus.RemoteAdmin.fdc

How to remove RemoteAdmin.Win32.Ammyy.cj?

RemoteAdmin.Win32.Ammyy.cj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment