Trojan

About “Trojan:Win32/Ramnit” infection

Malware Removal

The Trojan:Win32/Ramnit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ramnit virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Ramnit?


File Info:

crc32: ADF3170A
md5: 600240e9abc4655bb9412248e31f26a9
name: 3bf287ccdb6349e7e2d7f4f405b269f3dcc7d2704f46f2bdce57a37e376d4296.exe
sha1: 621fc528a8711cf2c57bc148d6cce56d00b91b1a
sha256: 3bf287ccdb6349e7e2d7f4f405b269f3dcc7d2704f46f2bdce57a37e376d4296
sha512: a57c2a0600bf6a29b75e06c132bbb037796f1801ded328cb8a51b8be52317e3d77be2a60f4496f140708d692a934e12d740e9fa61cd70c2827d01cee904bfc84
ssdeep: 6144:3OTeHI8HiL7+f5zkIMbyHgz7ESjAzMDeIrs:CeoGiLaSIC23h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2007 Avira GmbH. All rights reserved.
InternalName: AntiVir/Win32
FileVersion: 7.6.0.59
CompanyName: Avira GmbH
PrivateBuild:
LegalTrademarks: AntiVirxae is a registered trademark of Avira GmbH, Germany
Comments:
ProductName:
SpecialBuild:
ProductVersion: 7.6.0.59
FileDescription: AntiVir Command Line Scanner for Windows
OriginalFilename:
Translation: 0x0000 0x04b0

Trojan:Win32/Ramnit also known as:

BkavW32.HfsAutoB.1529
MicroWorld-eScanGen:Variant.Zusy.Elzob.24024
CAT-QuickHealW32.Ramnit.D
ALYacGen:Variant.Zusy.Elzob.24024
MalwarebytesSpyware.Zbot
VIPREVirus.Win32.Ramnit.a!dam (v)
BitDefenderGen:Variant.Zusy.Elzob.24024
K7GWVirus ( 0031ed2c1 )
K7AntiVirusVirus ( 0031ed2c1 )
AgnitumI-Worm.Chir.B
F-ProtW32/Ramnit.E
SymantecW32.Chir.B@mm
ESET-NOD32a variant of Win32/Chir.C
AvastWin32:Ramnit-BR [Trj]
ClamAVWIN.Worm.Brontok
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Runouce.bxafx
ViRobotWin32.Nimnul.A[h]
Ad-AwareGen:Variant.Zusy.Elzob.24024
SophosW32/Ramnit-BH
ComodoVirus.Win32.Ramnit.K
F-SecureGen:Variant.Zusy.Elzob.24024
DrWebWin32.HLLW.Tazebama.235
ZillyaTrojan.Chir.Win32.27
TrendMicroTROJ_GEN.R047C0CIB15
McAfee-GW-EditionBehavesLike.Win32.ZBot.dc
EmsisoftGen:Variant.Zusy.Elzob.24024 (B)
CyrenW32/Ramnit.E
JiangminHeur:Trojan/VB
AviraW32/Ramnit.C
FortinetW32/Kryptik.KLV!tr
Antiy-AVLWorm/Win32.Nimda.gic[NET]
ArcabitTrojan.Zusy.Elzob.D5DD8
SUPERAntiSpywareTrojan.Agent/Gen-FakeSecurity
AhnLab-V3Trojan/Win32.Zbot
MicrosoftTrojan:Win32/Ramnit
TotalDefenseWin32/Chir!remnants
McAfeePWS-Zbot.gen.cy
AVwareVirus.Win32.Ramnit.a!dam (v)
PandaTrj/Genetic.gen
ZonerWin32.Ramnit.A
RisingPE:Malware.XPACK!1.64E1[F1]
IkarusGen:Heur
GDataGen:Variant.Zusy.Elzob.24024
AVGWin32/Chir.I@mm
Qihoo-360Win32/Virus.52d

How to remove Trojan:Win32/Ramnit?

Trojan:Win32/Ramnit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment