Malware

About “RemoteAdmin.Win32.Generic” infection

Malware Removal

The RemoteAdmin.Win32.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RemoteAdmin.Win32.Generic virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:5931
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

rl.ammyy.com
www.ammyy.com
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine RemoteAdmin.Win32.Generic?


File Info:

crc32: A3312AD8
md5: aed3f0916a46993807451ef47834b008
name: ammyy.exe
sha1: c46d281b60b0d10b4a80b7e61237da1f1b77d622
sha256: 949f9f106f9256fea3780cecd7c9d4369d3c5cb2e5acb2077b5c49534458d766
sha512: 9f3490f91e93f454d8f82a4a9e868704b1db3d68fdb23c29ea79a9bea41044015e844a5257f6720f0a0018ee64d7ebe0b6602c09704b4ecb77b11b850478fa1a
ssdeep: 12288:zXe1Z2fJipMHEgSeA6M7kmchJGvRuORtcE9qTpy+Yg0HkV+Cgs5wh:DtkmHEgSewkmchJGsORtn9qT8+Yg03/9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.7
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.7
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

RemoteAdmin.Win32.Generic also known as:

MicroWorld-eScanGen:Variant.Application.RemoteAdmin.6
CAT-QuickHealTrojan.IGENERIC
K7GWUnwanted-Program ( 004b889d1 )
K7AntiVirusUnwanted-Program ( 004b889d1 )
Invinceaheuristic
CyrenW32/Trojan.BNAT-4033
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R007H0CLO18
AvastFileRepMalware [PUP]
Kasperskynot-a-virus:HEUR:RemoteAdmin.Win32.Generic
BitDefenderGen:Variant.Application.RemoteAdmin.6
NANO-AntivirusRiskware.Win32.RemoteAdmin.fhmdgm
Paloaltogeneric.ml
RisingMalware.Unwaders!8.FFE4 (CLOUD)
Ad-AwareGen:Variant.Application.RemoteAdmin.6
SophosGeneric PUA ME (PUA)
ComodoApplicUnwnt@#2i60h7ro4mfkx
DrWebProgram.RemoteAdmin.869
McAfee-GW-EditionBehavesLike.Win32.RemAdmAmmyy.bh
EmsisoftGen:Variant.Application.RemoteAdmin.6 (B)
SentinelOnestatic engine – malicious
JiangminRemoteAdmin.Ammyy.es
WebrootW32.Trojan.Ra
Antiy-AVLRiskWare[RemoteAdmin]/Win32.Ammyy
MicrosoftProgram:Win32/Vigram.A
Endgamemalicious (high confidence)
ArcabitTrojan.Application.RemoteAdmin.6
ZoneAlarmnot-a-virus:HEUR:RemoteAdmin.Win32.Generic
GDataWin32.Riskware.RemoteAdmin.A
AhnLab-V3Unwanted/Win32.RemoteAdmin.R239547
Acronissuspicious
McAfeeRemAdm-Ammyy
CylanceUnsafe
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
YandexRiskware.RemoteAdmin!
eGambitRAT.Ammyy
FortinetRiskware/RemoteAdmin_Ammyy
AVGFileRepMalware [PUP]
Cybereasonmalicious.16a469
PandaTrj/CI.A
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360Win32/Virus.RemoteAdmin.af5

How to remove RemoteAdmin.Win32.Generic?

RemoteAdmin.Win32.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment