Alert! Ransomware is Being Spread through the Ammyy Admin Website

  • 236
    Shares

This is a precautionary advisory for users who frequently visit the website of the popular remote desktop sharing software called Ammyy Admin.

Quick Heal Labs has observed that a new variant of the Cerber3 Ransomware is being spread through the Ammyy Admin software on the official Ammyy Admin website. This news, however, is not surprising as this website has been found to host malware on several other instances. In a previous case, the website was found to spread the notorious Cryptowall 4.0 Ransomware.

ammyy

Fig 1 Ammyy Admin official website

The Quick Heal Threat Research and Response Team recently observed increased cases of Cerber ransomware infections wherein the victims had downloaded and run the Ammyy Admin software from the original website. And our analysis of the malware found these observations to be true.

A technical analysis of the ransomware is available in this downloadable PDF.

PDF icon

 

 

 

How Quick Heal helps
Quick Heal Web Security feature proactively detects and blocks websites on the basis of their malicious reputation and inconsistency in delivering actual applications.

How to Stay Safe from the Cerber Ransomware?
• Avoid visiting the Ammyy Admin website.
• Remove the Ammyy Admin software if you have it on your computer.
• Do not respond to unknown or unwanted emails that urge you to click on links or download attachments, no matter how urgent such emails might sound.
• Run an antivirus software that detects and blocks infected websites and emails with malicious content.
• Take regular backups of your important files. Remember to disconnect the Internet when you are backing up on a hard drive. Unplug the drive before you go online again.
• Apply all recommended security updates (patches) to your Operating System, programs like Adobe, Java, Internet Browsers, etc. These updates fix security weaknesses in these programs and prevent malware from exploiting them.

 

ACKNOWLEDGMENT

Subject Matter Experts
• Shantanu Vichare
• Dipali Zure
– Threat Research and Response Team

Rajiv Singha

Rajiv Singha

Follow @Singha_Ra

Subscribe
Notify of
guest
104 Comments
Inline Feedbacks
View all comments
ROHIT SINGLA
ROHIT SINGLA
4 years ago

IS THERE ANY WAY TO RECOVER FILES IF IT IS ENCRYPTED BY CERBER 3 RANSOM WARE.

Amit Shah
Amit Shah
4 years ago

If your pc is infected by cetber 3 or crypto ransomeware then only spy hunter will remove the ransomeware. But problem is of encrypted data. Till today no software available for decrypt the data. When this ransomeware affected your pc no antivirus work and it also uses windows default services. After 20 hrs i am successful to remove cerber3 ransomeware from pc now i am working on decrypt the data. I give my suggestion for retriving data soon.

Sohan
Sohan
4 years ago

My PC attacked by cerber3 ransomware and all files encrypted. but i have seen a backup folder created by quick heal as backup function is inbuilt in quick heal in case of attack by ransomware. How can i restore file from quick heal. Please help me to get rid of this.

Anirban Dutta
Anirban Dutta
4 years ago

Thank you for your information. But please add Anti Phishing & Anti Spam on your Antivirus pro. Does it[Antivirus Pro] protect it’s user from Ransomware?

uttam singh
uttam singh
4 years ago

NOT SATISFIDE

Dinesh kumar
Dinesh kumar
4 years ago

Thanks for you

pongwa
pongwa
4 years ago

EnteIf the phone is stolen my questions I want to know where it’s close and give me instructions how to dor Message Here

Binod Kumar
Binod Kumar
4 years ago

Thanks for your email and help us,

RajeshMathe
RajeshMathe
4 years ago

hii m rajesh mathe from nagpur my laptop has been infected by ransomeware all my office data has been encripted .
is their any solution to bring back my data…
please help me…
call me if you have any chargeable or non-chargeable solution ..9970198781.

dhiraj
dhiraj
4 years ago

MY SYSTEM IS ALSO EFFECTED FROM IT AND MY FILE IS LOST AND AND WATN TO DECODE IT PLS HELP ME

dharamraj Bairwa
dharamraj Bairwa
4 years ago

it is awesome. I always enjoy it.

rajeshbst10@gmail.com
rajeshbst10@gmail.com
4 years ago

nice

reza seifi
reza seifi
4 years ago

Hello,please help in upgrade my antivirus,im buying for quick hill.to one month ago very very virus attack for my tablet

ranalab2000@gmail.com
ranalab2000@gmail.com
4 years ago

THE BEST ANTIVIRUR

asif
asif
4 years ago

i installed ammy admin with Ransomware .. it just creates @___readme___@ file and .cerber3 files in every folder.

but when i check my files it doesn’t encrypted at all… they just put that files in every directories nothing else….

julfikar islam
julfikar islam
4 years ago

OK

akjamphar51@gmail.com
akjamphar51@gmail.com
4 years ago

you are good

shefiu Akinde oyeleye
shefiu Akinde oyeleye
4 years ago

How can i recover my file back after been infected by the virus cerber3…..pls help

SK
SK
4 years ago

My laptop was detected with cerber ransomware. My system has crashed and my documents are corrupt. Is there anyway I can get back my files.

kundan
kundan
4 years ago

i am already infected with this virus and all my important files are encrypted. can someone please tell me how can i decrypt them.

Siva...
Siva...
4 years ago
Reply to  Rajib Singha

Hi Rajib,
I have infected this Ransomware virus using ammy admin software 9months before but your technical person no one is can’t able to decrypt the file. Finally i format my Lappy. I think it is not a easy to break the lock but If our system has restore point then we can rollback using old date

ekowkleen@gmail.com
ekowkleen@gmail.com
4 years ago

thanks the information

shubham jadhav
shubham jadhav
4 years ago

quick heal antivirus is important for pc,laptops,tab and other

Kamlesh Vaishya
Kamlesh Vaishya
4 years ago

How to recover Cerber3 Ransomware effected files?

Dave Stewart
Dave Stewart
4 years ago

Hi, could you answer me a couple of questions:-

1. Is it possible that the cerber virus can infect a slave hard drive so that if that drive is connected to a healthy PC it can still do some damage even if no executable file is launched from it?

2. I am a registered user of Ammyy admin and I have a clean version of the program but if I install a clean version on a remote PC and install the service mode could the people at Ammyy take over that PC through a back door??

Sanjai awasthi
Sanjai awasthi
4 years ago

Thank you for your information.

Ashish Kulkarni
Ashish Kulkarni
4 years ago

Unfortunately!!!! I am infected. Do Anti virus Pro edition removes this virus? Else i will have to purchase Norton edition.

Ricardo
Ricardo
4 years ago

Its true, Rajib Singha. I just noticed that.

Thank you.

Hatshad
Hatshad
4 years ago

Very good

Rajkamalgole
Rajkamalgole
4 years ago

I like this app

R.Muktesh
R.Muktesh
4 years ago

How to remove Ransomware and it using Quick Heal?

manikanta
manikanta
4 years ago

Thank u

SRIJIT BHAR
SRIJIT BHAR
4 years ago

Dear Sir,

I am Srijit by profession Computer Hardware Engineer, last 15 years I doing this work. As well as my company Dealer of Quick Heal. But last few months ago I don’t support properly for your company.
So, I requested that please tell me how to protect Ransom ware problem. Already our few clients suffer this problem, Example: NEWPL, ORIENT PAPERS, SHUBHAM EXPORTS, NEOGIE ENGINEERING WORKS And COSMON ENGINEERING. Please help me as early as possible.

prabir das
prabir das
4 years ago

my all the files encrypted through ransomware most probably suggest me how could i restore all this .

Rasel
Rasel
4 years ago

I’m Rasel . Today my PC attacked by the server3 ransomware . already my all file are destroyed. Photoshop and illustrator are don’t read file. And all file are already renamed . Pls suggests for me …

vikash jha
vikash jha
4 years ago

GOOD

VIPUL
VIPUL
4 years ago

Hello Sir,
I can’t update my antivirus database. It shows error that “please specify path”. Please suggest me solution.

Sumeet Anand
Sumeet Anand
4 years ago

unfortunately i used and downloaded ammy from its site all my files have been encrypted and got no idea how to get those back though i use quick heal and update on the daily basis, can u help me get my files back specially pictures

KUNAL KUMAR
KUNAL KUMAR
4 years ago

My product key not working ple. help

Prasanta Bhattacharyya
Prasanta Bhattacharyya
4 years ago

excellant

Anushka Yadav
Anushka Yadav
4 years ago

i did not go to the official website neither did i do any of the things that u ve mentioned in the case above but the cyber criminals ve encrypted all my files i ve even launched anti malware in quick heal still the problem remains unsolved what do i do now? plzz help all my files are encrypted!!!!!!!!!! 🙁

abhishek
abhishek
4 years ago

hiiiii i am abhishek singh this is a very sequre anti virus

sujeet kisku
sujeet kisku
4 years ago

I’m sujeet ,sir quick heal apps is to good….. it’s complete work….in mobile….ye hmesa mobile ke ram ko khali krta he jisse ki phone works very fast

deepaksamsl
deepaksamsl
4 years ago

It is the best a tivirous for mob and all

KP
KP
4 years ago

Hi Rajib,
My laptop got effected with this cerber3 ransomware virus. I have quick heal antivirus software installed and went to renew software license through your registered dealer or agent. First he had installed ammy admin software and tried to reniew the account and my laptop got affected. I have registered complaint with quick heal customer care also.

Please can you help me to how to restore my database.

shubhamverma767884@gmail.com
shubhamverma767884@gmail.com
4 years ago

GOOD ANTIVIRUS

vishal
vishal
4 years ago

sir unfortunately i am late to read these post and my office PC and house PC had been infected by cerber3 ransomware, and all my important file are now encrypted. have there been any solution to set it back to original condition other then paying those creep

Heyat ullah
Heyat ullah
4 years ago

it is the best one of the anti virous field.
i fully saticfy
my computer fully depend on it

Prashant Giri
Prashant Giri
4 years ago

Dear Sir,
I always promote your Antivirus for everyone though I don’t have any economical benefit. Now a day’s my client ‘Soham Motors’ is suffering from this Malware. They converted from other Antivirus to yours one. But still it’s not recovered. I physically found and tried to rename it as original, but could not recover whole file (mostly .MDB) we heartily request you please find a way to recover unscripted files. We saved whole on DVDs and formatted the Laptop. Please inform us on given email address
Thanks.
– Prashant Giri

Prashant Pandey
Prashant Pandey
4 years ago

Please Help Me

Koushik Roy
Koushik Roy
4 years ago

how to update?

104
0
Would love your thoughts, please comment.x
()
x