How to remove ammy_admin (1).exe
- File Details
- Overview
- Analysis
ammy_admin (1).exe
The module ammy_admin (1).exe has been detected as Risk.RemoteAdmin
File Details
Product Name: |
|
Company Name: |
|
MD5: |
2fa3823f28a02e5910abc38aa65cb63a |
Size: |
718 KB |
First Published: |
2017-05-22 10:26:09 (7 years ago) |
Latest Published: |
2020-05-31 09:21:42 (4 years ago) |
Status: |
Risk.RemoteAdmin (on last analysis) |
|
Analysis Date: |
2020-05-31 09:21:42 (4 years ago) |
Overview
Signed By: |
Ammyy |
Status: |
Valid |
%profile%\downloads |
%sysdrive%\afk\tuncer |
%sysdrive%\downloads\программы |
%mydoc%\disque 232\filehistory\philippe\phill\data\c\users\philippe\documents\pc pirate\softs\contrôle à distance |
%mydoc%\disque 232\disque 232\filehistory\philippe\phill\data\c\users\philippe\documents\pc pirate\softs\contrôle à distance |
%desktop%\chiavetta usb\dvd buffetti extra\support\vnc |
%sysdrive%\cd vrsoft\support\vnc |
%desktop%\chiavetta usb\dvd buffetti 4.040\support\vnc |
%desktop%\dvd buffetti\dvd buffetti 4.070\support\vnc |
%sysdrive%\aa |
AA_v3.1.exe |
ammy_admin (1).exe |
ammy_admin.exe |
AA_v3.exe |
AA_v3_2.exe |
AFKYardim.exe |
AA_v3.1 (2015_08_06 07_02_11 UTC).exe |
Remoto San.Com Infor 99506-4162.exe |
Ammyy_v3.1.exe |
AA_v3 (1).exe |
WindowsExplorer.exe |
aa_v3.exe |
AA_v3(1).exe |
|
14.5% |
|
|
10.8% |
|
|
10.8% |
|
|
9.6% |
|
|
8.4% |
|
|
8.4% |
|
|
6.0% |
|
|
6.0% |
|
|
6.0% |
|
|
4.8% |
|
|
3.6% |
|
|
2.4% |
|
|
2.4% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
Windows 7 |
48.8% |
|
Windows 10 |
40.5% |
|
Windows Server 2008 R2 |
4.8% |
|
Windows XP |
3.6% |
|
Windows Server 2012 R2 |
1.2% |
|
Windows 8 |
1.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00077c7e |
Name |
Size of data |
MD5 |
.text |
512000 |
90c2dc6e54005bff712999cc5da24889 |
.rdata |
69632 |
ed08907799cfa17b6550354c51027a88 |
.data |
98304 |
239eda3d278a2a9ba4dba777e167b002 |
.rsrc |
45056 |
8a83d77982f9887b3f9179096431330b |