Categories: Virus

Virus:Win32/Ramnit.A!remnants information

The Virus:Win32/Ramnit.A!remnants is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Ramnit.A!remnants virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
fget-career.com

How to determine Virus:Win32/Ramnit.A!remnants?


File Info:

crc32: 54A4E5D6md5: 4c1aed3638ecfa4ca5c02e8f9e3686abname: IDM.v6.xx.release.3-patch.exesha1: 149804823577e1733d33e020cd7b7ab3435a4641sha256: 922104a47af71cbbaecf79d084779f10fe0daf4be575a6ad3bc51be295147684sha512: 3c142305850060ad9642ae524a46794ba796fb09ee947d3e440941582c3cf5b635c12f4ffb65ce614b331d14ff6fbc1053c31c8809ecdffbf97e677dec72738essdeep: 12288:ht+fi4vNVAEuhHy4ocnOscYpeFenC3QXxD:X+jv09MIp4mC4Jtype: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Virus:Win32/Ramnit.A!remnants also known as:

Bkav W32.RammitNNA.PE
MicroWorld-eScan Win32.Ramnit
CAT-QuickHeal W32.Ramnit.A
McAfee W32/Ramnit.a
Malwarebytes HackTool.Agent
Zillya Virus.Nimnul.Win32.1
K7GW Virus ( 002fe95d1 )
K7AntiVirus Virus ( 002fe95d1 )
Arcabit Win32.Ramnit
TrendMicro PE_RAMNIT.H
Baidu Win32.Virus.Nimnul.a
F-Prot W32/Ramnit.B!Generic
Symantec W32.Ramnit!inf
TotalDefense Win32/Ramnit.A
TrendMicro-HouseCall PE_RAMNIT.H
ClamAV Win.Trojan.Ramnit-1847
GData Win32.Virus.Ramnit.C
Kaspersky Virus.Win32.Nimnul.a
BitDefender Win32.Ramnit
NANO-Antivirus Virus.Win32.Nimnul.bpchjo
AegisLab W32.Nimnul.tn4U
Avast Win32:RmnDrp
Tencent Virus.Win32.Ramnit.c
Ad-Aware Win32.Ramnit
Emsisoft Win32.Ramnit (B)
Comodo Packed.Win32.MPEC.Gen
F-Secure Win32.Ramnit
DrWeb Win32.Rmnet
VIPRE Virus.Win32.Ramnit.a (v)
Invincea virus.win32.ramnit.a
McAfee-GW-Edition BehavesLike.Win32.Ramnit.jh
Sophos W32/Patched-I
Ikarus Trojan.Graftor
Cyren W32/Ramnit.B!Generic
Jiangmin Win32/PatchFile.et
Webroot W32.RamNit.Gen
Avira W32/Ramnit.CD
Antiy-AVL Virus/Win32.Nimnul.a
Kingsoft Win32.Ramnit.la.30720
Endgame malicious (high confidence)
ViRobot Win32.Ramnit.E[h]
ZoneAlarm Virus.Win32.Nimnul.a
Microsoft Virus:Win32/Ramnit.A!remnants
AhnLab-V3 Win32/Ramnit.B
ALYac Win32.Ramnit
AVware Virus.Win32.Ramnit.a (v)
VBA32 Virus.Win32.Nimnul.a
Zoner Win32.Ramnit.A
ESET-NOD32 Win32/Ramnit.A
Rising Virus.Ramnit!1.9AA5 (classic)
Yandex Win32.Ramnit.Gen.3
SentinelOne static engine – malicious
Fortinet W32/Ramnit.A
AVG Win32/Ramnit.A
Panda W32/Cosmu.gen
CrowdStrike malicious_confidence_100% (D)
Qihoo-360 Virus.Win32.Ramnit.B

How to remove Virus:Win32/Ramnit.A!remnants?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Lazy.511346 information

The Lazy.511346 is considered dangerous by lots of security experts. When this infection is active,…

53 mins ago

Trojan.Generic.35768561 removal guide

The Trojan.Generic.35768561 is considered dangerous by lots of security experts. When this infection is active,…

53 mins ago

Should I remove “Win32:Bifrose-ESM [Trj]”?

The Win32:Bifrose-ESM [Trj] is considered dangerous by lots of security experts. When this infection is…

58 mins ago

GenPack:Win32.Rungbu.A removal instruction

The GenPack:Win32.Rungbu.A is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago

Fragtor.533034 (B) removal guide

The Fragtor.533034 (B) is considered dangerous by lots of security experts. When this infection is…

59 mins ago

Generic.KillMBR.A.4FE83A7C removal guide

The Generic.KillMBR.A.4FE83A7C is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago