Ammyy

Publisher Information

Ammyy is a software developer located in Москва, Russia*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove Ammyy Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
1/14/2014 5:30:00 AM

Valid to:
1/15/2015 5:29:59 AM

Subject:
CN=Ammyy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ammyy, L=Москва, S=Москва, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
52c9e020c4d675a668e1ddeb0ef1167b

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Ammyy.F, PUP.Service.Ammyy.H, PUP.Ammyy.V, PUP.Ammyy.G, PUP.Service.Ammyy.G, PUP.Ammyy (M)
100.00%

Kaspersky
not-a-virus:RemoteAdmin.Win32.Ammyy, Virus.Win32.Sality
82.86%

Dr.Web
Program.RemoteAdmin.701, riskware program Program.RemoteAdmin.701, Program.RemoteAdmin.758, Program.Ammyy.14
80.00%

NANO AntiVirus
Riskware.Win32.RemoteAdmin.dbfbaj, Riskware.Win32.RemoteAdmin.ctkgju, Riskware.Win32.RemoteAdmin.dbybgd, Virus.Win32.Sality.bzkem
80.00%

ESET NOD32
Win32/RemoteAdmin.Ammyy (variant), Win32/RemoteAdmin.Ammyy.B potentially unsafe
74.29%

VIPRE Antivirus
Remote-Access.Win32.Ammyy, Trojan.Win32.Generic, Threat.4734158, Threat.4721115, Threat.4747282
74.29%

Agnitum Outpost
Riskware.RemoteAdmin, Win32.Sality.FA.Gen
74.29%

Trend Micro House Call
Suspicious_GEN.F47V0627, TROJ_GEN.R0CBH07CD14, TROJ_GEN.R0CBH07CH14, Suspicious_GEN.F47V0703, TROJ_GEN.R047H07GL14, PE_SALITY.ER
71.43%

Rising Antivirus
PE:Malware.Ammyy!6.1139, PE:Win32.KUKU.GEN!1463551, PE:Win32.KUKU.kt!1591113, PE:Malware.Ammyy!6.2366, PE:Trojan.Habbo!6.24BC
71.43%

McAfee
Artemis!5616D57C2DA8, Artemis!3178F23055B2, Artemis!F8CD52B70A11, Artemis!2FCBAD97D444, Artemis!E72B313D807A, Artemis!2CBF5657FFD8, Artemis!84C868517F4D
68.57%

1 / 68      (Adware)
online_service_v3.5.exe (Ammyy-HiTechnic by Ammyy)  (29c4417b69581ad431e17d6956064748)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (f24e1e307966227dd330eb4a3ed506c5)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (cda357e3a1d0127e9bffe5110e80c0d6)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (dfaa5661a02f887bff2556c6c859cfbc)

17 / 68    (Adware)
aa_v3.4.exe (Ammyy Admin by Ammyy)  (95370c2cd8068f0c661ae98b97b8046b)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (141acbcc2c54543e346a2c779e5fd43e)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (9c24e7f335cae81f6128adee21b8c5cb)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (74e820afe55b32ac2e9b8804539bb186)

1 / 68      (Adware)
aa_v3.4.exe (Ammyy Admin by Ammyy)  (ac74025431787d599bbd713887ac4a0d)

24 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (081581104bfaf1d81c5515b7c20ff084)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (a76dcde4d48b2909b683644704651002)

24 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (2eb1b7a17075a206347c9fe2656b9825)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (81a9d190959c1576f0067aab5af36be2)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (2c6716645b45c3f4c436d554c931e9de)

1 / 68      (Adware)
aa_v3.4.exe (Ammyy Admin by Ammyy)  (054f2343565947fcb7b48e4595cdf0a8)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (37c084fd171b0709a594f11040f4dd18)

1 / 68      (Adware)

32 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (0c2dac93ac9f479175e07d7f19a773b1)

1 / 68      (Adware)
suporteremoto.exe (Ammyy Admin by Ammyy)  (662cf1fc2fb954c8d0291e857aa656ff)

33 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (42d5ad89bead6919fa3b6bdf8d9c33d8)

26 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (1529afcff4cb6a5399d0de545335b5be)

25 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (84c868517f4d92826737c1020c367c54)

25 / 68    (Adware)
fg-online support.exe (FG-Online Support by Future Games)  (d5ffd22e745120b0e7f9778d48e698ef)

13 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (923f85661df0af68a0e2621525cc9f03)

17 / 68    (Adware)
aa_v3.4.exe (Ammyy Admin by Ammyy)  (60f00ca0d17d34b5704f7184bcca281f)

17 / 68    (Adware)
aa_v3.4.exe (Ammyy Admin by Ammyy)  (c3254f617b48a5821dce7504f13d4088)

15 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (26c5005b85c01d3d38213a1f91e4f37f)

13 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (46f7f6a665c0e74bed19c6fcc2bf4905)

7 / 68      (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (2cbf5657ffd8858a9597f296a60270c2)

40 / 68    (Adware)
aa_v3.5.exe (Ammyy Admin by Ammyy)  (e72b313d807a536d45b68e52c1257996)

 
Latest 30 of 35 files

Downloads URLs for files signed by Ammyy.

7 / 68      (Adware)
http://www.msousalima.net/remoto.exe  (2cbf5657ffd8858a9597f296a60270c2)

12 / 68    (Adware)
http://ultracar.com.br/ammyy.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

7 / 68      (Adware)
http://www.i2a.es/AA_v3.5.exe  (2cbf5657ffd8858a9597f296a60270c2)

0 / 68
http://www.i2a.es/AA_v3.4.exe  (190785b2bb664324334c1b5231b5c4b0)

0 / 68
http://suporte.imoguia.com/.../Acesso3.exe  (190785b2bb664324334c1b5231b5c4b0)

7 / 68      (Adware)
http://www.global4.es/z4/.../g4ayuda1.exe  (2cbf5657ffd8858a9597f296a60270c2)

0 / 68
http://www.bmsoft.es/.../BMconex.exe  (190785b2bb664324334c1b5231b5c4b0)

7 / 68      (Adware)
http://www.halley.it/.../A-Assistenza.exe  (2cbf5657ffd8858a9597f296a60270c2)

7 / 68      (Adware)

12 / 68    (Adware)
http://www.gialive.com/.../AA_v3.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

7 / 68      (Adware)
https://www.kgieworld.co.th/.../AA_v3.5.exe  (2cbf5657ffd8858a9597f296a60270c2)

0 / 68
http://www.supplycokerala.com/download/.../AA_v3.4.exe  (190785b2bb664324334c1b5231b5c4b0)

0 / 68
http://dataservice.net.in:9080/.../AA_v3.4.exe  (190785b2bb664324334c1b5231b5c4b0)

12 / 68    (Adware)
ftp://uproc.lib.mi.us/.../AA_v3.5.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

12 / 68    (Adware)
http://201.20.32.82/suporte/.../Ammyy.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

0 / 68

0 / 68
http://www.tcrecargas.com.br/suporte.exe  (190785b2bb664324334c1b5231b5c4b0)

0 / 68
http://techboys123.com/.../Ammyy.exe  (190785b2bb664324334c1b5231b5c4b0)

12 / 68    (Adware)
http://www.iprog.com.br/precisa/remote/.../AA_v3.5.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

0 / 68
http://sigicorp.info/remota.exe  (190785b2bb664324334c1b5231b5c4b0)

0 / 68

12 / 68    (Adware)
http://boaideianet.com.br/.../AA_v3.exe  (f8cd52b70a11a1fb3f29c6f89ff971ec)

12 / 68    (Adware)
http://www.ellas.com.br/.../AMMYY_ADMIN_V3.EXE  (f8cd52b70a11a1fb3f29c6f89ff971ec)

40 / 68    (Adware)
http://www.finalcom.net/remotesupport.exe  (e72b313d807a536d45b68e52c1257996)

7 / 68      (Adware)
http://help.oitc.eu/AmmyyAdmin.exe  (2cbf5657ffd8858a9597f296a60270c2)

7 / 68      (Adware)
http://www.kamae.pt/AA_v3.exe  (2cbf5657ffd8858a9597f296a60270c2)

0 / 68
http://www.grupimatica.com/a.exe  (190785b2bb664324334c1b5231b5c4b0)

 
Latest 30 of 88 download URLs

The following websites host and distribute files published by Ammyy.

30 of 47 domains

The certificates below are also signed by Ammyy.

18CA484C639D98F0F877B32777CF778D  (Nov 11, 2012 to Dec 12, 2013)

5F442BEEED4174761DED2A9AEF47DE90  (Nov 04, 2011 to Nov 04, 2012)

The following publishers (by Authenticode signature organization name) are related.

30 of 75 publishers

Remove Ammyy Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Ammyy by VeriSign, Inc. on January 14, 2014 with the serial number '52c9e020c4d675a668e1ddeb0ef1167b'.