Malware

What is “Win32:RemoteAdmin-L [Tool]”?

Malware Removal

The Win32:RemoteAdmin-L [Tool] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:RemoteAdmin-L [Tool] virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

rl.ammyy.com

How to determine Win32:RemoteAdmin-L [Tool]?


File Info:

crc32: DE0863DB
md5: e74b76f8e3011e6c511db37502623c8e
name: DS.exe
sha1: 0935840523a2b79eff29ef7b0d996a42cf8907f1
sha256: 0a59d504157b33c9f09519c6f6fa4d25f23d0d50ee236bc715f6601d2fffc4a9
sha512: 072ebc6d761337899b0394a7f058427ed3702906c2aad12b045d313d3a5bab6aa937c20ddd982cacbc782a95a7dc70af41f755d5d3ccb45e415b61adadc9e53c
ssdeep: 12288:YX5PFc+E0SlpOvcC1KL/q/IZVURtCdshX5x8jR31QEY0VECgF0du:CP++ZSlpOUC1KT4+URtYshX5aRlQEY/R
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Ammyy Admin
FileVersion: 3.5
CompanyName: Ammyy LLC
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ammyy Admin
SpecialBuild:
ProductVersion: 3.5
FileDescription: Ammyy Admin
OriginalFilename:
Translation: 0x0409 0x04b0

Win32:RemoteAdmin-L [Tool] also known as:

MicroWorld-eScanGen:Variant.Application.RemoteAdmin.6
FireEyeGeneric.mg.e74b76f8e3011e6c
CAT-QuickHealTrojan.IGENERIC
McAfeeRemAdm-Ammyy
CylanceUnsafe
VIPRERemote-Access.Win32.Ammyy (not malicious)
AegisLabRiskware.Win32.Ammyy.1!c
K7AntiVirusHacktool ( 005519b11 )
BitDefenderGen:Variant.Application.RemoteAdmin.6
K7GWHacktool ( 005519b11 )
CrowdStrikewin/malicious_confidence_90% (D)
F-ProtW32/RemoteAdmin.C.gen!Eldorado
SymantecRemacc.Ammyy
APEXMalicious
AvastWin32:RemoteAdmin-L [Tool]
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.xrp
NANO-AntivirusRiskware.Win32.RemoteAdmin.euxmxo
Endgamemalicious (high confidence)
SophosGeneric PUA AJ (PUA)
ComodoApplication.Win32.RemoteAdmin.Ammyy.CA@6lncg7
DrWebProgram.RemoteAdmin.701
ZillyaTrojan.GenericKD.Win32.100289
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Application.RemoteAdmin.6 (B)
CyrenW32/RemoteAdmin.C.gen!Eldorado
JiangminRemoteAdmin.Ammyy.ey
WebrootW32.Ammyy.Wrj
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Application.RemoteAdmin.6
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.xrp
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Unwanted/Win32.RemoteAdmin.R218311
Acronissuspicious
PandaTrj/CI.A
ZonerTrojan.Win32.64955
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazruF9Ka9RIDwACJ96Sz+hdC)
YandexRiskware.RemoteAdmin!
SentinelOneDFI – Malicious PE
MaxSecureVirus.Trojan.Ammyy.wrj
FortinetRiskware/RemoteAdmin_Ammyy
Ad-AwareGen:Variant.Application.RemoteAdmin.6
AVGWin32:RemoteAdmin-L [Tool]
Cybereasonmalicious.8e3011
Paloaltogeneric.ml
Qihoo-360Win32/Virus.RemoteAdmin.ece

How to remove Win32:RemoteAdmin-L [Tool]?

Win32:RemoteAdmin-L [Tool] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment