Malware

What is “AIT.Heur.Ramy.1.54C78CF9.Gen”?

Malware Removal

The AIT.Heur.Ramy.1.54C78CF9.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT.Heur.Ramy.1.54C78CF9.Gen virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT.Heur.Ramy.1.54C78CF9.Gen?


File Info:

name: 703B62D121C3B9549411.mlw
path: /opt/CAPEv2/storage/binaries/550e776091240a4432f52c0e0c80cda9c9801db7be42c62952f92803aed10ea3
crc32: 41EB27D4
md5: 703b62d121c3b9549411cba1115b07fb
sha1: baff5407ada0166d3b1e60e3f55b6b1e8a348ec6
sha256: 550e776091240a4432f52c0e0c80cda9c9801db7be42c62952f92803aed10ea3
sha512: 4b778975ce3ecc6cdbc5f4e0e7a39bc3ef463e8a456af6b2dcaa4c6dcef2384d05f16c8cbdcd2d5ddd0b4b659ff61957ee112fedaff98379421f86573f7c755d
ssdeep: 24576:iwWHhK2FjW8WVKsVu8aPJNiMDMOv9wQStz2O2kQWryTuZAOMrozV/pDqSZwvI:9WHhKejW8gKsVu8avinOv9wQStahkQWg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D635332B4DE40174E9A384B4D73EB1E43B6CE9A0DE04FF49B699A46C057C1E65232B73
sha3_384: 46ecb998b9a30ea07880b6e4102b29bc3e37964ed65977d1c78de93224c843b6222faf9889d5735f617a4fe1b85a48b2
ep_bytes: 60be000046008dbe0010faff5783cdff
timestamp: 2016-11-10 09:18:03

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileVersion: 15.0.23.0
LegalCopyright: Copyright 2016 Avira Operations GmbH & Co. KG. All rights reserved.
OriginalFilename: ManagedFirewall_SysTray.exe
ProductName: Avira Swat Apl Rs
ProductVersion: 15.0.23.0
Translation: 0x0809 0x04b0

AIT.Heur.Ramy.1.54C78CF9.Gen also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ramy.4!c
DrWebTrojan.BtcMine.1084
MicroWorld-eScanAIT.Heur.Ramy.1.54C78CF9.Gen
ClamAVWin.Malware.Autoit-6992293-0
CAT-QuickHealTrojan.Autcobit
ALYacAIT.Heur.Ramy.1.54C78CF9.Gen
MalwarebytesGeneric.Malware.AI.DDS
VIPREAIT.Heur.Ramy.1.54C78CF9.Gen
SangforTrojan.Win32.Autcobit.Vgwi
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutCobit.40531dd7
K7GWTrojan ( 700000111 )
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.CVNCQCE
APEXMalicious
CynetMalicious (score: 100)
BitDefenderAIT.Heur.Ramy.1.54C78CF9.Gen
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Autcobit.Vwhl
EmsisoftAIT.Heur.Ramy.1.54C78CF9.Gen (B)
F-SecureTrojan.TR/AutCobit.ucgte
TrendMicroTROJ_GEN.R002C0DGR23
McAfee-GW-EditionBehavesLike.Win32.Injector.tc
Trapminemalicious.moderate.ml.score
FireEyeAIT.Heur.Ramy.1.54C78CF9.Gen
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.CDL9ON
AviraTR/AutCobit.ucgte
Antiy-AVLHackTool/Win32.Agent
ArcabitAIT.Heur.Ramy.1.54C78CF9.Gen [many]
MicrosoftTrojan:Win32/AutCobit
GoogleDetected
AhnLab-V3Trojan/Win32.Nymeria.C2495045
McAfeeArtemis!703B62D121C3
MAXmalware (ai score=87)
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DGR23
RisingTrojan.Generic@AI.100 (RDML:6c0OuCp//XoTHayef8TkJA)
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove AIT.Heur.Ramy.1.54C78CF9.Gen?

AIT.Heur.Ramy.1.54C78CF9.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment