Ammyy

Publisher Information

Ammyy is a software developer located in Moscow, Russian Federation in Russia*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove Ammyy Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
11/12/2012 5:30:00 AM

Valid to:
12/13/2013 5:29:59 AM

Subject:
CN=Ammyy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ammyy, L=Moscow, S=Russian Federation, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
18ca484c639d98f0f877b32777cf778d

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Service.Ammyy.F, PUP.Service.Ammyy.G, PUP.Ammyy.I, PUP.Service.Ammyy.H, PUP.Ammyy.F, PUP.Ammyy.N, PUP.Ammyy (M)
100.00%

NANO AntiVirus
Riskware.Win32.Ammyy.cqmwzu, Trojan.Win32.RemoteAdmin.cqzmlg, Trojan.Win32.RemoteAdmin.cqkogb, Riskware.Win32.RemoteAdmin.ctckhy, Trojan.Win32.RemoteAdmin.cfosvy
56.67%

Rising Antivirus
PE:Malware.Ammyy!6.854, PE:Malware.Ammyy!6.1139
53.33%

K7 Gateway Antivirus
Unwanted-Program , Trojan
50.00%

K7 AntiVirus
Unwanted-Program , Trojan
50.00%

Kaspersky
not-a-virus:RemoteAdmin.Win32.Ammyy
50.00%

ESET NOD32
Win32/RemoteAdmin.Ammyy, Win32/RemoteAdmin.Ammyy (variant), Win32/RemoteAdmin.Ammyy.C potentially unsafe (variant)
46.67%

Jiangmin
RemoteAdmin.Ammyy.q, RemoteAdmin.Ammyy.d, RemoteAdmin.Ammyy.ei
46.67%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Malware.Generic.a.(kcloud), Win32.Troj.Ammyy.aq.(kcloud), Win32.Troj.Ammyy.an.(kcloud)
46.67%

Antiy Labs AVL
RemoteAdmin/Win32.Ammyy, RiskWare[RemoteAdmin:not-a-virus]/Win32.Ammyy, RiskWare[RemoteAdmin]/Win32.Ammyy.z
43.33%

1 / 68      (Adware)
remoto.exe (Ammyy Admin by Ammyy)  (b690f970678c91eaf1cf0f244e86b3f3)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (6b7a709a4c6981a8836085bdf6ecfe46)

1 / 68      (Adware)
ammy v3.2.exe (Ammyy Admin by Ammyy)  (6c9b1bf2923def428e538671b925c5bf)

1 / 68      (Adware)
aa_v3.1.exe (Ammyy Admin by Ammyy)  (43da89345737883a7dd232e40d85fb87)

1 / 68      (Adware)
aa_v3.3.exe (Ammyy Admin by Ammyy)  (660d781bc10d94cf1e8337d806eb2ba1)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (adcebd0a5f975989697a82863b1e2282)

1 / 68      (Adware)
aa_v3.2.exe (Ammyy Admin by Ammyy)  (8ebdb52aa4c53fdf3184b8142d2e5c48)

1 / 68      (Adware)
aa_v3.1.exe (Ammyy Admin by Ammyy)  (67c9773cad387575457c5a25c20fdcc5)

1 / 68      (Adware)
soporte sysvicon.exe (Ammyy Admin by Ammyy)  (ff3d07e57591472c9e7a0cf0d01e3fc3)

1 / 68      (Adware)
ammyy.exe (Ammyy Admin by Ammyy)  (616ab5c366b82d890797fdb20a599d34)

1 / 68      (Adware)
aa_v3-3.exe (Ammyy Admin by Ammyy)  (54ceb0de1414cfb2843d7e8bce4b012c)

1 / 68      (Adware)
aa_v3.1.exe (Ammyy Admin by Ammyy)  (5917f4fc321d57a2208c77c53e9a9c21)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (0178843ea495fdaf369137eed8bd13f5)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (024f369bed6d016940ef1e2848fc2852)

1 / 68      (Adware)
aa_v3.2.exe (Ammyy Admin by Ammyy)  (5ac3739c81eded7641da76a9588e58eb)

1 / 68      (Adware)
aa_v3.2.exe (Ammyy Admin by Ammyy)  (ef14dbbde9d430b9bdb3b493347f3a94)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (d54bb68f9015b3d7091f5ef3262bf697)

13 / 68    (Adware)
aa_v3.1.exe (Ammyy Admin by Ammyy)  (8ef2330c474af300a7785f0b0ea2d2f8)

1 / 68      (Adware)
ammyy.exe (Ammyy Admin by Ammyy)  (d76882203cb660e4fab0fc109dbb97b9)

23 / 68    (Adware)
ammyy_full.exe (Ammyy Admin by Ammyy)  (7ac5fbbb214da5d99bf94244e42e459b)

27 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (5ad7a778c09dc558ad2d162dca5c0879)

7 / 68      (Adware)
ammyadmin_v3.2.exe (Ammyy Admin by Ammyy)  (a22d9016f8dcd8c07782d78a7aa3b2e1)

14 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (517d18ec10a6f3839845545207d664d4)

14 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (b5276926ad52e7bd68031a1a52ebdcd7)

29 / 68    (Adware)
svchost.exe (Ammyy Admin by Ammyy)  (3cf537f0598ec4add06e27bfa8799793)

29 / 68    (Adware)
supp0rt1.exe (Ammyy Admin by Ammyy)  (4de1f1cc5f953cc0cb91ee9fb9c10521)

11 / 68    (Adware)
aa_v3.1.exe (Ammyy Admin by Ammyy)  (9561c8f7bd981a9eaac23ec6fa9a65e5)

13 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (2fa3823f28a02e5910abc38aa65cb63a)

31 / 68    (Adware)
aa_v3.3.exe (Ammyy Admin by Ammyy)  (d22d719495f23e38805bbea5df434abb)

16 / 68    (Adware)
AA_v3.exe (Ammyy Admin by Ammyy)  (45c9b54d66cbcc2de89f93e25f368a45)

 
Latest 30 of 30 files

Downloads URLs for files signed by Ammyy.

13 / 68    (Adware)
https://b2b.csq.es/.../remoto2.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://www.mkbrasiltelecom.com.br/.../AA_v3.1.exe  (2fa3823f28a02e5910abc38aa65cb63a)

31 / 68    (Adware)
http://www.onedownloader.com/.../ammyyadmin.exe  (d22d719495f23e38805bbea5df434abb)

16 / 68    (Adware)
http://www.egg.com.br/.../AA_v3.exe  (45c9b54d66cbcc2de89f93e25f368a45)

13 / 68    (Adware)
http://www.acacioseguridad.com/.../AA_v3.exe  (2fa3823f28a02e5910abc38aa65cb63a)

11 / 68    (Adware)
ftp://ftp.bhiwal.com/.../AA_v3.1.exe  (9561c8f7bd981a9eaac23ec6fa9a65e5)

13 / 68    (Adware)

16 / 68    (Adware)

13 / 68    (Adware)
http://www.nutrilifesoftware.com.br/.../AA.exe  (2fa3823f28a02e5910abc38aa65cb63a)

16 / 68    (Adware)
http://tech678.com/ammyy.exe  (45c9b54d66cbcc2de89f93e25f368a45)

16 / 68    (Adware)
http://coinfru.com/.../AA_v3.exe  (45c9b54d66cbcc2de89f93e25f368a45)

13 / 68    (Adware)
http://ljsistemas.net/.../Ammyy.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://www.optiplus.es/.../remoto0.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://151.co.il/ammy_admin_old.exe  (2fa3823f28a02e5910abc38aa65cb63a)

31 / 68    (Adware)
http://toolboox.com/.../ammyy-admin.exe  (d22d719495f23e38805bbea5df434abb)

11 / 68    (Adware)
http://www.sensysindia.com/SensysAmmy.exe  (9561c8f7bd981a9eaac23ec6fa9a65e5)

11 / 68    (Adware)
http://www.doctornet.com.br/.../AA_v3.exe  (9561c8f7bd981a9eaac23ec6fa9a65e5)

11 / 68    (Adware)
http://www.ypsylon.com/.../AA_v3.exe  (9561c8f7bd981a9eaac23ec6fa9a65e5)

16 / 68    (Adware)
http://eped.bahiagrafica.com.br/AA_v3.exe  (45c9b54d66cbcc2de89f93e25f368a45)

16 / 68    (Adware)
http://novo.valenet.com.br/.../AA_v3.exe  (45c9b54d66cbcc2de89f93e25f368a45)

13 / 68    (Adware)
http://www.150.co.il/ammy_admin_old.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://350.co.il/ammy_admin.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://dc340.4shared.com/download/.../ammyy_admin_31.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://www.econnect.ws/.../AA_v3.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://marketingsystem.com.br/.../suporte2.exe  (2fa3823f28a02e5910abc38aa65cb63a)

13 / 68    (Adware)
http://150.co.il/ammy_admin3_1.exe  (2fa3823f28a02e5910abc38aa65cb63a)

 
Latest 30 of 55 download URLs

The following websites host and distribute files published by Ammyy.

The certificates below are also signed by Ammyy.

52C9E020C4D675A668E1DDEB0EF1167B  (Jan 14, 2014 to Jan 15, 2015)

5F442BEEED4174761DED2A9AEF47DE90  (Nov 04, 2011 to Nov 04, 2012)

The following publishers (by Authenticode signature organization name) are related.

Remove Ammyy Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Ammyy by VeriSign, Inc. on November 12, 2012 with the serial number '18ca484c639d98f0f877b32777cf778d'.