Ammyy

Publisher Information

Ammyy is a software developer located in Moscow, Russia*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove Ammyy Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
11/4/2011 5:30:00 AM

Valid to:
11/4/2012 5:29:59 AM

Subject:
CN=Ammyy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ammyy, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5f442beeed4174761ded2a9aef47de90

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Ammyy.F, PUP.Ammyy.P, PUP.Service.Ammyy.F, PUP.Ammyy.E, PUP.Ammyy.I, PUP.Service.Ammyy.K, PUP.Ammyy.U, PUP.Startup.Ammyy.P, PUP.Ammyy (M), PUP.Ammyy.MXSoft (M)
100.00%

Jiangmin
RemoteAdmin.Agent.e, RemoteAdmin.Ammyy.c, RemoteAdmin.Ammyy.a, RemoteAdmin.Ammyy.h, RemoteAdmin.Ammyy.g
72.41%

ESET NOD32
Win32/RemoteAdmin.Ammyy (variant)
72.41%

Rising Antivirus
PE:Malware.Ammyy!6.854, PE:Trojan.Win32.Generic.12ACEA95!313322133
72.41%

Kaspersky
not-a-virus:RemoteAdmin.Win32.Agent, not-a-virus:RemoteAdmin.Win32.Ammyy
68.97%

Kingsoft AntiVirus
Win32.Malware.Generic.a.(kcloud), Win32.Troj.Agent.yf.(kcloud), Win32.HeurC.KVM019.a.(kcloud)
68.97%

Bkav FE
W32.Clod820.Trojan, W32.Clod22a.Trojan, W32.Clodebd.Trojan, W32.Clodc44.Trojan
68.97%

avast!
Win32:PUP-gen [PUP]
68.97%

Antiy Labs AVL
RemoteAdmin/Win32.Ammyy.gen, Trojan[RemoteAdmin:not-a-virus]/Win32.Ammyy
68.97%

Avira AntiVirus
SPR/RemoteAdmin.AB, SPR/RemoteAdmin.AN.1, APPL/Remote.AmmyyAdmin.214, APPL/Remote.AmmyyAdmin.129
68.97%

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (a95811eb0396d070da0708d6d3e33af9)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (7808da8e83e739b4a1a67ed2d7e2ff40)

1 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by MX Soft)  (483ad30d9f1afe99021204c913ec7ec2)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (15086fb549cce291105bbe197fa60287)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (10890e521eacc27338aa7bc66e8fb8e6)

1 / 68      (Adware)
aa_v3.0.exe (Ammyy Admin by Ammyy)  (2fb4195722fd4933076d541ccfa67e87)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (7057a9b1a27bb3366f2ca7627d70ee63)

1 / 68      (Adware)
c&d remoto.exe (Ammyy Admin by Ammyy)  (6218fa9aba231d928ebacc0ffbf749d9)

1 / 68      (Adware)
ammyy admin v3.exe (Ammyy Admin by Ammyy)  (2400febc587fa3432a2e65e27232f600)

1 / 68      (Adware)
egt remote support.exe (Ammyy Admin by Ammyy)  (b735ff2c61e99e9d0a112a6cdf4dcc61)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (606ed4c70ef85de7e1087b64a9b8facc)

19 / 68    (Adware)
lmhost.exe (Ammyy Admin by Ammyy)  (7037be973d7d20fd13881b12e4b2ea63)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (2b1ac4f741431bc827522a2454736c25)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (c2cd448b8d9f06c1c2083b8315ffb7e9)

1 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by MX Soft)  (c78ce1f5a721868debc3c7eb45acd5a9)

20 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (df7acf1591e6cb5f3d434ecb68a7b871)

20 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (3cd46aa0e216dc8a67a5a99499c1f7bb)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (e6eeded729ebd42a03d6d80922893a00)

8 / 68      (Adware)
agrip_fernwartung_v3.exe (Ammyy Admin by Ammyy)  (61e9063d98bd8ceb0eb78332996e1fe5)

20 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (b9b5ca19815cd592e7a4113076839b7c)

17 / 68    (Adware)
aa_v3_corp.exe (Ammyy Admin by Ammyy)  (1eac56f9b5d5c033eff40ce59809264a)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (2104f66da494fb2cac8d654f02cd85d7)

12 / 68    (Adware)
ammyy_v3.exe (Ammyy Admin by Ammyy)  (8f302247960cc514d3400eab4842e006)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (3734ddaae611c76ff66b879a3366090a)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (84e1a6646ba5637ba5b30e6565202dfd)

10 / 68    (Adware)
aav3.exe (Ammyy Admin by Ammyy)  (18e6fbf3a7799ead04694742028458de)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (c59be0a84718d97a82cfa59860bdab3a)

1 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by MX Soft)  (483ad30d9f1afe99021204c913ec7ec2)

21 / 68    (Adware)
aa_v3.exe (Ammyy Admin by Ammyy)  (f9cde592fcd907fb00807124df17c2f1)

Downloads URLs for files signed by Ammyy.

21 / 68    (Adware)
http://www.oooooo.us/ammy.exe  (f9cde592fcd907fb00807124df17c2f1)

20 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (b9b5ca19815cd592e7a4113076839b7c)

21 / 68    (Adware)
http://www.fix247.org/AA_v3.exe  (c59be0a84718d97a82cfa59860bdab3a)

20 / 68    (Adware)
https://dl.dropboxusercontent.com/u/.../suporte/AA_v3.exe  (b9b5ca19815cd592e7a4113076839b7c)

10 / 68    (Adware)
http://downloads.motilaloswal.com/Dwn/.../ammy.exe  (18e6fbf3a7799ead04694742028458de)

21 / 68    (Adware)
http://touchstore.ie/TouchStoreHome/.../AMMYY_Admin.exe  (c59be0a84718d97a82cfa59860bdab3a)

21 / 68    (Adware)

21 / 68    (Adware)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (f9cde592fcd907fb00807124df17c2f1)

21 / 68    (Adware)
https://app.barakdiamonds.com/.../AA_v3.exe  (f9cde592fcd907fb00807124df17c2f1)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (e6eeded729ebd42a03d6d80922893a00)

21 / 68    (Adware)
http://infosis.net/tv.exe  (84e1a6646ba5637ba5b30e6565202dfd)

21 / 68    (Adware)
http://www.contronic.com.br/.../aremoto.exe  (2104f66da494fb2cac8d654f02cd85d7)

21 / 68    (Adware)
http://www.winbooks.com.br/.../AA_v3.exe  (f9cde592fcd907fb00807124df17c2f1)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (2104f66da494fb2cac8d654f02cd85d7)

21 / 68    (Adware)

21 / 68    (Adware)
http://www.fidelizaralcliente.com/remoto.exe  (84e1a6646ba5637ba5b30e6565202dfd)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.skyperec.com/MXSkypeRecorder.exe  (483ad30d9f1afe99021204c913ec7ec2)

21 / 68    (Adware)
http://193.238.136.83/AA_v3.exe  (c59be0a84718d97a82cfa59860bdab3a)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.0.exe  (c59be0a84718d97a82cfa59860bdab3a)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (3734ddaae611c76ff66b879a3366090a)

21 / 68    (Adware)
http://www.ammyy.com/AA_v3.exe  (c59be0a84718d97a82cfa59860bdab3a)

21 / 68    (Adware)
http://150.co.il/ammy_admin.exe  (f9cde592fcd907fb00807124df17c2f1)

The following websites host and distribute files published by Ammyy.

The certificates below are also signed by Ammyy.

52C9E020C4D675A668E1DDEB0EF1167B  (Jan 14, 2014 to Jan 15, 2015)

18CA484C639D98F0F877B32777CF778D  (Nov 11, 2012 to Dec 12, 2013)

The following publishers (by Authenticode signature organization name) are related.

Remove Ammyy Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Ammyy by VeriSign, Inc. on November 04, 2011 with the serial number '5f442beeed4174761ded2a9aef47de90'.