Trojan

Should I remove “Trojan.Ranumbot”?

Malware Removal

The Trojan.Ranumbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ranumbot virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ranumbot?


File Info:

crc32: 9CC2E92C
md5: 8f8d710c0c50497680610b9fbe572980
name: upload_file
sha1: 6411bb27df4b77a8bfc7534c2349f18b81f2c7af
sha256: 67d53f916dfaa58825da5c4141cbb338b286aab1de054bd46c0c1f989519491f
sha512: e6d29166bcd67d21886a11e6aa8aefd0f2f476847e73d24b353165f841386ec8e29cf902074d48f92b2aef06ab7f31375a7517a6043fe4a665de69a973df5ae5
ssdeep: 12288:xAx1HbQRy6GftfBheI9VPm2fiN8WggmIFCsEjlUe1ddn59AgQ2jiVH+quod:xAvcRyvFfB48VPnKN8FgZ4v1xn599XG
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Ranumbot also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34307115
FireEyeGeneric.mg.8f8d710c0c504976
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!8F8D710C0C50
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056664f1 )
BitDefenderTrojan.GenericKD.34307115
K7GWTrojan ( 0056664f1 )
Cybereasonmalicious.c0c504
TrendMicroTROJ_GEN.R011C0PH820
BitDefenderThetaGen:NN.ZexaF.34152.SmGfaa1R1dp
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
AlibabaTrojan:Win32/RanumBot.4c2bc7c1
NANO-AntivirusTrojan.Win32.Redcap.hrbcyc
ViRobotTrojan.Win32.Z.Ranumbot.722944
TencentWin32.Trojan.Generic.Eehx
Ad-AwareTrojan.GenericKD.34307115
EmsisoftTrojan.GenericKD.34307115 (B)
F-SecureTrojan.TR/Redcap.pzcow
FortinetW32/RanumBot.Y!tr
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.YVOE-5261
WebrootW32.Trojan.Gen
AviraTR/Redcap.pzcow
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.RanumBot
ArcabitTrojan.Generic.D20B7C2B
MicrosoftTrojan:Win32/Ymacco.AA67
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34307115
MalwarebytesTrojan.Ranumbot
PandaTrj/CI.A
ESET-NOD32a variant of Win32/RanumBot.Y
TrendMicro-HouseCallTROJ_GEN.R011C0PH820
RisingTrojan.RanumBot!8.112AC (CLOUD)
IkarusTrojan.Win32.Ranumbot
GDataTrojan.GenericKD.34307115
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Generic/Trojan.16a

How to remove Trojan.Ranumbot?

Trojan.Ranumbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment