Spy Trojan

TrojanSpy:Win32/Ranbyus.P removal instruction

Malware Removal

The TrojanSpy:Win32/Ranbyus.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Ranbyus.P virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine TrojanSpy:Win32/Ranbyus.P?


File Info:

crc32: AF65B28E
md5: ae16af7a610c9e7463d2a8ba47339f4d
name: AE16AF7A610C9E7463D2A8BA47339F4D.mlw
sha1: 9c9dca15206e19db7ff30ce1ae39ac9bdb921140
sha256: 60ab6ed7bb8225258c62abd1e7375d7a23a108b1b05e4538a708ca69e192d734
sha512: 47dbbc833b9879b2779a635ebfb3c3a2bfab823951c459fa6cde7ba75d21b8ff5861f9f02290b9a9b8341e8c2734a7044a134da5221f7b1b48d84c4a919f7139
ssdeep: 6144:eEFUnKLJ8Ial4g9ZI7+eJlt6pZKegu9a5qARIYrcl3q3XDlUI/bWMDnX:BFUnKt8ILgoBlAZ/gCEVKYAuhVblX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 2016
InternalName: Chess
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Chess
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Chess
OriginalFilename: Chess.exe
Translation: 0x040f 0x04e4

TrojanSpy:Win32/Ranbyus.P also known as:

K7AntiVirusTrojan ( 0056fe4d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4993
CynetMalicious (score: 100)
CAT-QuickHealRansom.Teerac.F4
ALYacGen:Variant.Midie.30750
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056fe4d1 )
Cybereasonmalicious.a610c9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DBDF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-7082663-1
KasperskyTrojan-Ransom.Win32.Scatter.w
BitDefenderGen:Variant.Midie.30750
NANO-AntivirusTrojan.Win32.Encoder.evihqj
SUPERAntiSpywareRansom.Locker/Variant
MicroWorld-eScanGen:Variant.Midie.30750
TencentMalware.Win32.Gencirc.10b587a2
Ad-AwareGen:Variant.Midie.30750
SophosML/PE-A + Mal/Zbot-UM
BitDefenderThetaGen:NN.ZexaF.34670.yq3@a4jgwizf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXAC-VL!AE16AF7A610C
FireEyeGeneric.mg.ae16af7a610c9e74
EmsisoftGen:Variant.Midie.30750 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Locky.drr
AviraHEUR/AGEN.1108490
eGambitUnsafe.AI_Score_73%
MicrosoftTrojanSpy:Win32/Ranbyus.P
ArcabitTrojan.Midie.D781E
GDataGen:Variant.Midie.30750
AhnLab-V3Trojan/Win32.Nitol.C1492813
McAfeeGenericRXAC-VL!AE16AF7A610C
MAXmalware (ai score=97)
VBA32Hoax.Scatter
MalwarebytesSpyware.Boaxxe
PandaTrj/CI.A
RisingRansom.Scatter!8.139C (CLOUD)
YandexTrojan.GenAsa!ESciwHmFhRk
IkarusTrojan.Win32.Boaxxe
FortinetW32/Injector.DBDF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwcBAIcC

How to remove TrojanSpy:Win32/Ranbyus.P?

TrojanSpy:Win32/Ranbyus.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment