Malware

RemoteAdmin.Win32.Ammyy.xxc removal instruction

Malware Removal

The RemoteAdmin.Win32.Ammyy.xxc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Ammyy.xxc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

rl.ammyy.com

How to determine RemoteAdmin.Win32.Ammyy.xxc?


File Info:

crc32: 4933F5A0
md5: c4b63f13a483722c1af9a924cf84ca60
name: C4B63F13A483722C1AF9A924CF84CA60.mlw
sha1: d83eac5628c457cfff08154a51f7257c80cd5b39
sha256: 1a3b1acb6f1aed53f4f2f465c720cf730c0de9006fc29cbd259e72ace226c8d5
sha512: f745e7b650a791abf0c29bb768da08ad6c3d06fde535fce14bd451ac59c5a0d61b31f3b5ac60fbcbffd6b47a9e5dfb760e42ccdb2cfe10e6d9eea4127aec7edc
ssdeep: 6144:mI645btLNyvopVBbFiuWi8h9GF89v2K2O5gPGHB71he6bwd9vyBCscwCHD/:xJbLb/ias9Get2O5g6m64yBCsdCHL
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Microsoft inc. All right reserved
InternalName: SQL server
FileVersion: 9.5
CompanyName: Microsoft inc
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: SQL server
SpecialBuild:
ProductVersion: 9.5
FileDescription: SQL service
OriginalFilename: Sqlsvc.exe
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Ammyy.xxc also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005376ae1 )
LionicRiskware.Win32.Ammyy.1!c
DrWebProgram.RemoteAdmin.863
McAfeeArtemis!C4B63F13A483
CylanceUnsafe
SangforPUP.Win32.RemoteAdmin.RIQ
BitDefenderApplication.RemoteAdmin.RIQ
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.3a4837
CyrenW32/Threat-SysVenFakP-based!Max
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
APEXMalicious
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.xxc
NANO-AntivirusRiskware.Win32.RemoteAdmin.egaxvy
MicroWorld-eScanApplication.RemoteAdmin.RIQ
Ad-AwareApplication.RemoteAdmin.RIQ
SophosMal/Generic-R + Mal/ZboCheMan-I
ComodoApplication.Win32.RemoteAdmin.Ammyy.CA@6lncg7
BitDefenderThetaGen:NN.ZexaF.34236.ti1faqeLeapi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.fc
FireEyeApplication.RemoteAdmin.RIQ
EmsisoftApplication.RemoteAdmin.RIQ (B)
SentinelOneStatic AI – Malicious PE
JiangminRemoteAdmin.Ammyy.ew
WebrootW32.Ammyy.Ra
Antiy-AVLTrojan/Generic.ASBOL.211
MicrosoftTrojan:Win32/Occamy.C
ArcabitApplication.RemoteAdmin.RIQ
GDataApplication.RemoteAdmin.RIQ
AhnLab-V3Unwanted/Win32.RemoteAdmin.C3563072
MAXmalware (ai score=97)
PandaTrj/CI.A
YandexRiskware.RemoteAdmin!d2rNji2J7fg
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/RemoteAdmin_Ammyy
Paloaltogeneric.ml

How to remove RemoteAdmin.Win32.Ammyy.xxc?

RemoteAdmin.Win32.Ammyy.xxc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment