Spy Trojan

TrojanSpy:Win32/Ranbyus.A information

Malware Removal

The TrojanSpy:Win32/Ranbyus.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Ranbyus.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Ranbyus.A?


File Info:

name: C9ABE2D3150FD6F52BB3.mlw
path: /opt/CAPEv2/storage/binaries/41e8e6d78772edb16d203ea1440681e3e56264e4c2ba10f58d88d7cde624dea7
crc32: 0B1AC7A8
md5: c9abe2d3150fd6f52bb3b3b80012415d
sha1: bd5da61685d84748908ac36dad1c1bf1feffe0fa
sha256: 41e8e6d78772edb16d203ea1440681e3e56264e4c2ba10f58d88d7cde624dea7
sha512: 2d55bf7c133115f24939558f1b1b66861bc88d0dc0f99df24860e35e0a056f03c078fafd94c9b934765b7ea466a133a2f1f64247da6b24e91f743b3cb74ffa60
ssdeep: 6144:Y1oyIkjbkUquRxf08nrxhWdjDwK+FIsX7zfzhfj:9yIkjvqqfRrxcjUHtfzh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13334125595304100E708E67E3B3A9E78F4F750769E2FAEC39B68DFB821055E2A95203F
sha3_384: a2fbb14fdce77ab3bdd61fed87b12b4be120ba4c32ed45de63f47a77cc65767d4aaf41e25bc93c8a1fa8f25fb7d13a72
ep_bytes: 6a2868e8103f00e89301000033ff57ff
timestamp: 2010-03-23 22:23:43

Version Info:

0: [No Data]

TrojanSpy:Win32/Ranbyus.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Agent-420035
FireEyeGeneric.mg.c9abe2d3150fd6f5
ALYacGen:Variant.Zbot.11
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.59741
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojanSpy:Win32/Ranbyus.755bddc9
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.AB.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CNK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.11
NANO-AntivirusTrojan.Win32.TrjGen.iiiqm
MicroWorld-eScanGen:Variant.Zbot.11
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Taox
Ad-AwareGen:Variant.Zbot.11
EmsisoftGen:Variant.Zbot.11 (B)
ComodoTrojWare.Win32.Trojan.Generic.36270720@2ncwxm
DrWebTrojan.Siggen.64379
VIPREGen:Variant.Zbot.11
TrendMicroTSPY_RANBYUS.SM
McAfee-GW-EditionPWS-Subbyna.gen.a
Trapminesuspicious.low.ml.score
SophosML/PE-A + Mal/Generic-L
IkarusTrojan-Spy.Win32.Ranbyus
GDataGen:Variant.Zbot.11
JiangminTrojan/Generic.evt
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Zbot.11
MicrosoftTrojanSpy:Win32/Ranbyus.A
GoogleDetected
AhnLab-V3Worm/Win32.IRCBot.R62357
Acronissuspicious
McAfeePWS-Subbyna.gen.a
MAXmalware (ai score=100)
VBA32TrojanSpy.Ranbyus
MalwarebytesMalware.AI.4145027868
TrendMicro-HouseCallTSPY_RANBYUS.SM
RisingSpyware.Ranbyus!8.85D (TFE:5:P02NU5SYBKE)
YandexTrojan.GenAsa!QXsln8nHQvg
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
BitDefenderThetaGen:NN.ZexaF.34606.puZ@aeD4cfp
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3150fd
PandaTrj/Genetic.gen

How to remove TrojanSpy:Win32/Ranbyus.A?

TrojanSpy:Win32/Ranbyus.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment