Virus

About “Virus.Win32.Ramnit” infection

Malware Removal

The Virus.Win32.Ramnit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Ramnit virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Virus.Win32.Ramnit?


File Info:

crc32: CA3A1C51
md5: a0ee51371cfcafccfb7e866a2016e954
name: A0EE51371CFCAFCCFB7E866A2016E954.mlw
sha1: efd34355ea8fd1ab6e613856254c201ccf0db0cb
sha256: caaa0d689922ca138f10d5f36c59fae414a8a0bca24adc3ef57e996302c311a8
sha512: 16bc00f0fbc3a205fc3f1ab660c69c788db638552a2a5be291abd13f05f8bf2802efd8e36c9f64e70f9b0997086a703803dac3e514b249f0584052a09d915fd1
ssdeep: 3072:ZqPL1/7w6ZAs+VBKWGCHu6ZCWYwMpuSNUQH:+QVgp64J7u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-2000
InternalName: copymar
FileVersion: 6.10.0016.1624
CompanyName: Microsoft Corporation
Built by: msnbld
ProductName: Microsoft(R) MSN (R) Communications System
ProductVersion: 6.10.0016.1624
FileDescription: copymar
OriginalFilename: copymar.exe
Translation: 0x0409 0x04b0

Virus.Win32.Ramnit also known as:

LionicVirus.Win32.Nimnul.m1R5
Elasticmalicious (high confidence)
DrWebBackDoor.Darkshell.246
CynetMalicious (score: 100)
CAT-QuickHealW32.Ramnit.EB3
ALYacWin32.Ramnit
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.71cfca
CyrenW32/Ramnit.B!Generic
SymantecW32.Wapomi.C!inf
ESET-NOD32Win32/Ramnit.A
APEXMalicious
AvastWin32:RmnDrp [Inf]
ClamAVWin.Trojan.Vjadtre-6170948-0
KasperskyHEUR:Virus.Win32.Ramnit.gen
BitDefenderWin32.Ramnit
NANO-AntivirusVirus.Win32.Ramnit.eslalb
MicroWorld-eScanWin32.Ramnit
TencentWin32.Virus.Nimnul.Lmuo
Ad-AwareWin32.Ramnit
BitDefenderThetaAI:FileInfector.EAEEA7850C
VIPRETrojan.Win32.Generic!BT
TrendMicroPE_RAMNIT.H
McAfee-GW-EditionBehavesLike.Win32.Virut.ch
FireEyeGeneric.mg.a0ee51371cfcafcc
EmsisoftWin32.Ramnit (B)
AviraW32/Jadtre.B
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Virus.Win32.Ramnit.gen
GDataWin32.Ramnit (2x)
McAfeeW32/PatchedSmall.a!dam
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1877675480
PandaGeneric Suspicious
TrendMicro-HouseCallPE_RAMNIT.H
YandexWin32.Ramnit.Gen.3
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Nimnul.A
FortinetW32/Wapomi.BA!tr
AVGWin32:RmnDrp [Inf]
Paloaltogeneric.ml

How to remove Virus.Win32.Ramnit?

Virus.Win32.Ramnit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment