Ammyy Group

Publisher Information

Ammyy Group is a software developer located in Moscow, Russia*. The company is a primary distributor of unwanted software.
Remove Ammyy Group Malware - Powered by Reason Core Security
Authority:
The USERTRUST Network

Valid from:
6/5/2009 5:30:00 AM

Valid to:
6/6/2010 5:29:59 AM

Subject:
CN=Ammyy Group, O=Ammyy Group, STREET=Novocheremushkinskaya 53-4, L=Moscow, S=Moscow, PostalCode=117418, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0092ef3f37216c5b81115d14b285dcad6b

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AmmyyGroup.L, PUP.Startup.AmmyyGroup.P, PUP.AmmyyGroup.P, PUP.AmmyyGroup.O, PUP.AmmyyGroup.N, PUP.Ammyy.AmmyyGroup (M)
100.00%

ESET NOD32
Win32/RemoteAdmin.Ammyy (variant), Win32/RemoteAdmin.Ammyy.B potentially unsafe (variant)
56.25%

AhnLab V3 Security
Win-AppCare/Remoteaammyy.667344, Win-Trojan/Malware.561064
31.25%

Rising Antivirus
PE:Malware.Agent!6.FD5
25.00%

Kaspersky
not-a-virus:RemoteAdmin.Win32.Agent, not-a-virus:RemoteAdmin.Win32.Ammyy
18.75%

Jiangmin
RemoteAdmin.Agent.b
18.75%

Bkav FE
W32.Clod052.Trojan, W32.Clodf7f.Trojan, W32.HfsAdware
18.75%

NANO AntiVirus
Riskware.Win32.Ammyy.csrlye, Riskware.Win32.Ammyy.caeuws, Riskware.Win32.Ammyy.ddfrgh
18.75%

CMC Antivirus
RemoteAdmin.Win32.Agent!O
18.75%

McAfee
Artemis!C66CF6BD36A1, Artemis!55458C983615, Artemis!3CA783BA67E3
18.75%

5 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (b6f000506a20edba6e16fcf774ca6f05)

1 / 68      (Adware)
ammyy_admin.exe_bak (Ammyy Admin)  (e06cb672eaa33e18e72fe944b5937f45)

1 / 68      (Adware)
suporte.exe (Midia Tecnologia)  (3d18270469834c27d59d3c749acc6f6d)

1 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (44b7d85ba12b2a88b843ad0f23f27225)

5 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (cee61f99f9b0b9e118ff49d8405ece85)

17 / 68    (Adware)
teleassistenza_23.exe (Ammyy Admin)  (3ca783ba67e3c079e8d65137c0187700)

3 / 68      (Adware)
ammyy_admin.exe (Ammyy Admin)  (9a61028cd5c2fc473499f3b1dbc07bdf)

4 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (10c182e0e705aa72cdb4491752f8f2e0)

23 / 68    (Adware)
suporteremoto.exe (Mastertech Sistemas)  (55458c9836159cc786319350ed25d0bb)

3 / 68      (Adware)
ammyy_admin.txt (Ammyy Admin)  (4f62db72149a80b51779e6ab6c4f5dbb)

1 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by Ammyy Group)  (81a04bcd15156be9672c0d3cc5bd1d6a)

2 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (a2e84731b8f6db867c958be975cfbb31)

2 / 68      (Adware)
AMMYY_Admin.exe (Ammyy Admin)  (8556b95310d176654cae4ca119b59949)

2 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by Ammyy Group)  (258cc4d89cd4a455e019d3a895cfb339)

1 / 68      (Adware)
MXSkypeRecorder.exe (MX Skype Recorder by Ammyy Group)  (398d6c59df99c74fc83a802f8865f107)

26 / 68    (Adware)
saga_remote.exe (Ammyy Admin)  (b730e7b8f3eebd51dc21d7997313b890)

Downloads URLs for files signed by Ammyy Group.

26 / 68    (Adware)
http://www.sagasoft.ro/.../saga_remote.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://htds.com.br/admin/arquivos/.../AMMYY_Admin.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://www.todorecargas.com/.../soporte.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://www.ammyy.com/AMMYY_Admin.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://www.ex.ua/.../22092662  (saga_remote.exe)

26 / 68    (Adware)
http://systemar.com.br/suporte3.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://www.tcig.de/remote.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://help.duocomputers.com/  (saga_remote.exe)

26 / 68    (Adware)
http://www.rss-llc.com/.../aa.exe  (b730e7b8f3eebd51dc21d7997313b890)

1 / 68      (Adware)
http://dl.cdn.chip.de/downloads/.../MXSkypeRecorder43.exe  (398d6c59df99c74fc83a802f8865f107)

26 / 68    (Adware)
http://www.ammyy.com/AA_v2.exe  (b730e7b8f3eebd51dc21d7997313b890)

26 / 68    (Adware)
http://www.matach24.com/AMMYY_Admin.exe  (b730e7b8f3eebd51dc21d7997313b890)

The following websites host and distribute files published by Ammyy Group.

The following publishers (by Authenticode signature organization name) are related.

Remove Ammyy Group Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Ammyy Group by The USERTRUST Network on June 05, 2009 with the serial number '0092ef3f37216c5b81115d14b285dcad6b'.