Trojan

What is “Trojan.Ranapama.EW”?

Malware Removal

The Trojan.Ranapama.EW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ranapama.EW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Ranapama.EW?


File Info:

name: C7AD011BF34FD256573C.mlw
path: /opt/CAPEv2/storage/binaries/6653f09c9e8034ec7afe589e13c928e893d7e2aa55ccad2ebd2ef518e7e62c27
crc32: 16BAEC6D
md5: c7ad011bf34fd256573ced9a39826610
sha1: f4c5baae5ce67ed443024fbe2a5472923d944933
sha256: 6653f09c9e8034ec7afe589e13c928e893d7e2aa55ccad2ebd2ef518e7e62c27
sha512: 1b0a748a06a8022e09bd0cb91cc98d3539c8154dc65ab7e65e45986df1e802cc9b82d75436992d0b5f8c175a708f005377284ba83fe0fd6dd85f26fb17a22b5f
ssdeep: 1536:Ht9JhsliAfBBLVAiZFEPN/mCsdXaKqR2HG4vuag:HLEHjVJvCYBkZMq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED83DF5FC075B673F8BEF5B0454D066E63E2D9260EB69937AE401F0E4C35216AF0168E
sha3_384: 8019b1572b064a696468b5f2a96ec03696af2cd0b25ccc6fa0570de4504fad51fb67cf853a3d9d2c322cc010dd3ea612
ep_bytes: 558bec6aff68503a4000689022400064
timestamp: 2015-06-28 07:28:10

Version Info:

0: [No Data]

Trojan.Ranapama.EW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.todA
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Ranapama.EW
FireEyeGeneric.mg.c7ad011bf34fd256
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-EZ!C7AD011BF34F
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Ranapama.EW
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/DllCheck.8f639f6b
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.e5ce67
BitDefenderThetaGen:NN.ZexaF.36662.fqW@a04oCjh
VirITTrojan.Win32.Inject2.CMIH
CyrenW32/S-bee4d96e!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.CERP
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ranapama.EW
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Injector-CSV [Trj]
TencentMalware.Win32.Gencirc.10b5fd1c
EmsisoftTrojan.Ranapama.EW (B)
BaiduWin32.Trojan.Injector.j
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader14.49148
ZillyaTrojan.Injector.Win32.278363
McAfee-GW-EditionPacked-EZ!C7AD011BF34F
Trapminemalicious.high.ml.score
SophosMal/Zbot-UE
IkarusTrojan.Inject2
GDataTrojan.Ranapama.EW
JiangminBackdoor/Hlux.gku
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent.iftj
XcitiumBackdoor.Win32.Hlux.AMG@5sucfd
ArcabitTrojan.Ranapama.EW
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/DllCheck.A!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R157330
VBA32OScope.Malware-Cryptor.Hlux
ALYacTrojan.Ranapama.EW
TACHYONBackdoor/W32.Hlux.82634.B
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Dorv!8.422 (TFE:4:2nR8PNavjMU)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.CERA!tr
AVGWin32:Injector-CSV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Ranapama.EW?

Trojan.Ranapama.EW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment