Malware

What is “RemoteAdmin.Win32.Ammyy.wrj”?

Malware Removal

The RemoteAdmin.Win32.Ammyy.wrj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Ammyy.wrj virus can do?

  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

rl.ammyy.com

How to determine RemoteAdmin.Win32.Ammyy.wrj?


File Info:

crc32: 69F4E921
md5: 11bc606269a161555431bacf37f7c1e4
name: 11BC606269A161555431BACF37F7C1E4.mlw
sha1: 63c52b0ac68ab7464e2cd777442a5807db9b5383
sha256: 1831806fc27d496f0f9dcfd8402724189deaeb5f8bcf0118f3d6484d0bdee9ed
sha512: 0be867fce920d493d2a37f996627bceea87621ba4071ae4383dd4a24748eedf7dc5ca6db089217b82ec38870248c6840f785683bf359d1014c7109e7d46dd90f
ssdeep: 12288:XVFUEuNmwvGrw9i0aTGRGicBckyyFRtWY1i3FTsvOVV0gz:3UEUUw9RaTNicBrPFRtJ1iVTsC5z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Ammyy.wrj also known as:

BkavW32.HfsAdware.3C2B
DrWebProgram.RemoteAdmin.701
CyrenW32/RemoteAdmin.ACSY-7276
SymantecSMG.Heur!cg1
AhnLab-V3Unwanted/Win32.RemoteAdmin
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
AvastWin32:RemoteAdmin-B [PUP]
F-ProtW32/RemoteAdmin.Ammyy
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.wrj
JiangminTrojan.Generic.fyyq
NANO-AntivirusRiskware.Win32.AmmyAdmin.dskdxp
AviraSPR/RemoteAdmin.765952
SUPERAntiSpywareHackTool/Gen-Ammyy
Antiy-AVLRiskWare[RemoteAdmin:not-a-virus]/Win32.Ammyy
GDataWin32.Riskware.RemoteAdmin.A
AVGRemoteAdmin.DEQ
AegisLabRemoteAdmin.W32.Ammyy.vwt!c
YandexRiskware.RemoteAdmin!

How to remove RemoteAdmin.Win32.Ammyy.wrj?

RemoteAdmin.Win32.Ammyy.wrj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment