Trojan

Trojan:Win32/Ramnit!MSR removal tips

Malware Removal

The Trojan:Win32/Ramnit!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ramnit!MSR virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

i.imgur.com

How to determine Trojan:Win32/Ramnit!MSR?


File Info:

crc32: 91C8F25E
md5: 918b4df1f8d7b1e18e3e8fccdef3f5de
name: upload_file
sha1: 9b8f84e2d239252c83d89c3179f53893574c97a1
sha256: 62bd38c89d1a30b03bd89a788d9f2852659f77715c97e5c12445c33f43fa13e5
sha512: bd6f8633285547160039a0730f936944f47336af5eda702332de7c23c6eefc2b3a19160dd235d1b5e18ecaefd9949ee847a1875949beac921f5890b6d3f841b8
ssdeep: 24576:oEhFMGyXUHAW3S69Y2iBwdFQ4cN9bIV9XUNbW4f:Tio4GrcbW4f
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ramnit!MSR also known as:

MicroWorld-eScanTrojan.GenericKD.34716722
FireEyeTrojan.GenericKD.34716722
CAT-QuickHealTrojan.Shellcode
McAfeeArtemis!918B4DF1F8D7
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 00570acf1 )
BitDefenderTrojan.GenericKD.34716722
K7GWTrojan-Downloader ( 00570acf1 )
TrendMicroTROJ_FRS.0NA103J820
CyrenW32/Trojan.MJSO-1791
SymantecTrojan Horse
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Exploit.Win32.Shellcode.gen
AlibabaTrojanDownloader:Win32/Rugmi.8dfe441b
NANO-AntivirusExploit.Win32.Shellcode.hzcedn
ViRobotTrojan.Win32.S.Agent.1014984
Ad-AwareTrojan.GenericKD.34716722
EmsisoftMalCert-S.CQ (A)
ComodoMalware@#ib4i3262ep6o
DrWebBackDoor.Rat.281
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Rugmi
JiangminTrojan.Invader.dgy
Antiy-AVLTrojan[Exploit]/Win32.ShellCode
MicrosoftTrojan:Win32/Ramnit!MSR
ArcabitTrojan.Generic.D211BC32
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataTrojan.GenericKD.34716722
ALYacBackdoor.RAT.Parallax
MAXmalware (ai score=87)
VBA32Backdoor.Rat
MalwarebytesExploit.ShellCode
PandaTrj/CI.A
ESET-NOD32Win32/TrojanDownloader.Rugmi.AAE
TrendMicro-HouseCallTROJ_FRS.0NA103J820
RisingTrojan.Generic@ML.88 (RDMK:nNGasZ1UU9kspC7IB8maKA)
FortinetW32/Rugmi.FAH!tr.dldr
WebrootW32.Trojan.Gen
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Exploit.7ee

How to remove Trojan:Win32/Ramnit!MSR?

Trojan:Win32/Ramnit!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment