Virus

About “Virus:Win32/Ramnit.I!remnants” infection

Malware Removal

The Virus:Win32/Ramnit.I!remnants is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Ramnit.I!remnants virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Japanese
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Ramnit.I!remnants?


File Info:

name: 59FCF93A5E1205E08E4C.mlw
path: /opt/CAPEv2/storage/binaries/4f1f19b2732b185d4218bfe1382ebaa2fa9a3c6ad32a7fe6f273b0d4067f3fa4
crc32: 22E3CC17
md5: 59fcf93a5e1205e08e4c1b649fb40680
sha1: d0cc380871ac478f1592042c17642d6b131fa88a
sha256: 4f1f19b2732b185d4218bfe1382ebaa2fa9a3c6ad32a7fe6f273b0d4067f3fa4
sha512: 0c2acd900fd59caf1cd300fbfb7c92db8d51257064ec84c9745ffacbb58d7df29b4a16269c39284c7a1b82a612f9f03a24513e1282c164318eb4e41bf2fbf798
ssdeep: 3072:kGxU54CODu9MX9HIKd6IEVg2QHXyW0U+J:hxeODu9TVLQHXyW/+J
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A5D302009AE49571FEC999BA36015E07852BD23117D1D5C3AFF0BBD90C6F2A3EEA114B
sha3_384: abb1b751d3421ecee4cd1255680bf1a81b9cc1c484119f10d5665f0d719a6fd93e1d3c63fee3d7100608d2923474a63e
ep_bytes: 837c2408017505e802040000ff742404
timestamp: 2009-08-26 05:02:53

Version Info:

CompanyName: SEIKO EPSON CORPORATION
FileVersion: 2, 0, 0, 0
LegalCopyright: Copyright (C) SEIKO EPSON CORPORATION 2005-2008, All rights reserved.
ProductName: UtilImageFile TGA Plugin
ProductVersion: 2.00
Translation: 0x0411 0x04b0

Virus:Win32/Ramnit.I!remnants also known as:

MicroWorld-eScanWin32.Ramnit.Dam
FireEyeGeneric.mg.59fcf93a5e1205e0
CAT-QuickHealW32.Ramnit.D
SkyhighW32/Ramnit!trace
McAfeeW32/Ramnit!trace
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:FileInfector.FE0962FA10
ESET-NOD32a variant of Win32/Ramnit.CG
BitDefenderWin32.Ramnit.Dam
NANO-AntivirusVirus.Win32.Nimnul.fntoeg
AvastWin32:Ramnit-CC [Trj]
EmsisoftWin32.Ramnit.Dam (B)
BaiduWin32.Virus.Nimnul.dam
F-SecureMalware.W32/Ramnit.C
VIPREWin32.Ramnit.Dam
CMCVirus.Win32.RamnitDam.1!O
SophosW32/Patched-I
IkarusW32.Ramnit
GoogleDetected
AviraW32/Ramnit.C
VaristW32/Patched.B!Generic
Antiy-AVLVirus/Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.I!remnants
XcitiumVirus.Win32.Ramnit.OV@3uwchz
ArcabitWin32.Ramnit.Dam
ViRobotWin32.Ramnit.B
GDataWin32.Virus.Nimnul.A
CynetMalicious (score: 99)
ALYacWin32.Ramnit.Dam
MAXmalware (ai score=80)
Cylanceunsafe
RisingVirus.Ramnit!1.B97C (CLASSIC)
MaxSecureVirus.W32.Nimnul.A
FortinetW32/Ramnit.DAM!tr
AVGWin32:Ramnit-CC [Trj]
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Ramnit.PUMYXIGXSWGYFRDZQHTFZLJLMI

How to remove Virus:Win32/Ramnit.I!remnants?

Virus:Win32/Ramnit.I!remnants removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment