Trojan

Trojan.Ranapama.JE removal instruction

Malware Removal

The Trojan.Ranapama.JE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ranapama.JE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Ranapama.JE?


File Info:

name: 15ECE89EEF9910797221.mlw
path: /opt/CAPEv2/storage/binaries/f237bfdd46384bca00c8d22311c5d348a41fb41aad9aba6c59d035ae9b80441c
crc32: F67C54A5
md5: 15ece89eef9910797221128fc9c98291
sha1: 7e861c1729058b937d9799389eed02f18ff3f483
sha256: f237bfdd46384bca00c8d22311c5d348a41fb41aad9aba6c59d035ae9b80441c
sha512: fa975fff570dd95f971023acd7288db13ccade9aebe4f061862d7b456a64d2a68b69fa06df6c6d64e34b4e14d1d5c4b780edbab858581d38d260a7f1f6722b6b
ssdeep: 1536:Hvl4iY3nWWrL7Qe25xjlU47I0m93i6E2i:94iWC5xjlr7I1i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171A392BF7F090472DA64663022F7C3CA02666C195F4BA54BA60477B92DE3E440D7EB1B
sha3_384: ea510e8ebe4bf7518c54ad5ce55bb48d9dfe5c8f9f15e761f386963ebf7267b220d3ebeb78f7a389991c510c4827ef44
ep_bytes: 6878124000e8eeffffff000000000000
timestamp: 2012-07-25 06:52:50

Version Info:

Translation: 0x0409 0x04b0
Comments: Reseam candida
CompanyName: Reseam candida
FileDescription: Reseam candida
LegalCopyright: Reseam candida
LegalTrademarks: Reseam candida
ProductName: Reseam candida
FileVersion: 8.74
ProductVersion: 8.74
InternalName: coperchio
OriginalFilename: coperchio.exe

Trojan.Ranapama.JE also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Ranapama.JE
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.15ece89eef991079
CAT-QuickHealTrojan.VobfusMF.S21116242
McAfeeVBObfus.ek
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BaiduWin32.Worm.VB.ad
VirITTrojan.Win32.Zyx.MM
CyrenW32/VB.HC.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AXU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.lyq
BitDefenderTrojan.Ranapama.JE
NANO-AntivirusTrojan.Win32.Vobfus.jutdbv
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADVE [Trj]
TencentWorm.Win32.Vobfus.q
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Autorun.GO
DrWebWin32.HLLW.Autoruner1.23820
VIPRETrojan.Ranapama.JE
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nt
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ranapama.JE (B)
IkarusWorm.Win32.VBNA
GDataTrojan.Ranapama.JE
JiangminTrojan/Vbobf.b
WebrootW32.Worm.Ge
AviraTR/Autorun.GO
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Sasfis.A@1l3dev
ArcabitTrojan.Ranapama.JE
ZoneAlarmTrojan.Win32.Vobfus.lyq
MicrosoftWorm:Win32/Vobfus.GE
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R31661
BitDefenderThetaGen:NN.ZevbaF.36196.gm0@aKcMsWoi
ALYacTrojan.Ranapama.JE
TACHYONTrojan/W32.Vobfus.98304
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingTrojan.VBInject!1.64F2 (CLASSIC)
YandexTrojan.GenAsa!1mtQQxWHC1E
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4540632.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADVE [Trj]
Cybereasonmalicious.eef991
DeepInstinctMALICIOUS

How to remove Trojan.Ranapama.JE?

Trojan.Ranapama.JE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment