Malware

How to remove “RemoteAdmin.Win32.Ammyy.xzx”?

Malware Removal

The RemoteAdmin.Win32.Ammyy.xzx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Ammyy.xzx virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:5931
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

rl.ammyy.com
www.ammyy.com
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine RemoteAdmin.Win32.Ammyy.xzx?


File Info:

crc32: F2948225
md5: 79910ca3e3418acca4fa2f2e16bac1a3
name: Ammyy_3.7.exe
sha1: e2619c3d2580aa37c579835fdd3c5efee3f22412
sha256: 7aeab9459e2a833d56e474a23ab56bc66645a89ff8ef175050d8b0bed74d090e
sha512: 0e5ae373f2c1f9c8ba03338c2b5c520c6c1b1fa6ad38bcfa52f926634e1f65fac1cbd50af96c6e4d873424c38a1dd4c985d5fdc5de12a5827c76852340bffb5a
ssdeep: 12288:/Xe1Z2fJipMHEgSeA6M7kmchJGvRuORtcE9qTpy+Yg0HkV+QgM:ftkmHEgSewkmchJGsORtn9qT8+Yg03FM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.7
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.7
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Ammyy.xzx also known as:

BkavW32.HfsAdware.3C2B
DrWebProgram.RemoteAdmin.869
MicroWorld-eScanGen:Variant.Application.RemoteAdmin.6
FireEyeGeneric.mg.79910ca3e3418acc
Qihoo-360Win32/Trojan.Adware.37e
McAfeeRemAdm-Ammyy
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Ammyy.1!c
K7AntiVirusHacktool ( 005519b11 )
BitDefenderGen:Variant.Application.RemoteAdmin.6
K7GWHacktool ( 005519b11 )
Cybereasonmalicious.3e3418
ArcabitTrojan.Application.RemoteAdmin.6
TrendMicroHKTL_AMMYADMN
SymantecRemacc.Ammyy
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallHKTL_AMMYADMN
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.xzx
AlibabaRiskWare:Win32/Ammyy.7aa6f87d
NANO-AntivirusRiskware.Win32.Ammyy.hanqww
Ad-AwareGen:Variant.Application.RemoteAdmin.6
EmsisoftGen:Variant.Application.RemoteAdmin.6 (B)
ComodoMalware@#38u20txvnhamy
ZillyaTool.Ammyy.Win32.15
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.RemAdmAmmyy.bh
SentinelOneDFI – Malicious PE
JiangminExploit.BypassUAC.bgx
WebrootW32.Ammyy.Wrj
FortinetRiskware/Ammyy
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.xzx
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.RemoteAdmin.R239547
APEXMalicious
RisingTrojan.Generic@ML.100 (RDMK:S19r3XJbj8+21vj1BUF2/Q)
YandexTrojan.Igent.bRQrPz.8
MAXmalware (ai score=100)
eGambitRAT.Ammyy
GDataWin32.Riskware.RemoteAdmin.A
AVGFileRepMalware [PUP]
AvastFileRepMalware [PUP]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.Trojan.Ammyy.wrj

How to remove RemoteAdmin.Win32.Ammyy.xzx?

RemoteAdmin.Win32.Ammyy.xzx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment