Virus

Virus:Win32/Ramnit.P removal guide

Malware Removal

The Virus:Win32/Ramnit.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Ramnit.P virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Virus:Win32/Ramnit.P?


File Info:

crc32: EB7AE539
md5: 352c7b8546aa436e244f5cac759d4844
name: 2-l.exe
sha1: db03f89930d4ffbc92d382ef08df29b83a171747
sha256: 4d2cb01bc393cb422810c178dea443df1bcd71cd5a56826ce38fcd363753b0fa
sha512: 3c20dc6689cb9c864f55940a1610bc310d66811bfbac4467178e1c3158333d8dad3ff64cdaf2a18332ea51120aea413814dd105247d2b8b55c8799eb4d9f97fd
ssdeep: 12288:caJ8C5M/iotv+HlaIxaoyUsEFP+WPtdpqL1sJhQqP:cyvI+HlFxPyBzWPtzJhQqP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TODO: (c) . All rights reserved.
InternalName: SeminariaQwest.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: SeminariaQwest.exe
Translation: 0x0409 0x04e4

Virus:Win32/Ramnit.P also known as:

BkavW32.Tmgrtext.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Ramnit.N
FireEyeGeneric.mg.352c7b8546aa436e
CAT-QuickHealW32.Ramnit.BA
ALYacWin32.Ramnit.N
CylanceUnsafe
ZillyaVirus.Nimnul.Win32.1
SangforMalware
K7AntiVirusVirus ( 002fe95d1 )
BitDefenderWin32.Ramnit.N
K7GWVirus ( 002fe95d1 )
Cybereasonmalicious.546aa4
TrendMicroPE_RAMNIT.DEN
BitDefenderThetaAI:FileInfector.9425D5100E
F-ProtW32/Ramnit.B!Generic
SymantecW32.Ramnit.B!inf
ESET-NOD32Win32/Ramnit.H
BaiduWin32.Virus.Nimnul.a
TrendMicro-HouseCallPE_RAMNIT.DEN
AvastWin32:RmnDrp
ClamAVWin.Trojan.Ramnit-1847
KasperskyVirus.Win32.Nimnul.a
NANO-AntivirusVirus.Win32.Nimnul.fntoeg
ViRobotWin32.Nimnul.A
RisingVirus.Mgr!1.9AD0 (CLASSIC)
Ad-AwareWin32.Ramnit.N
ComodoVirus.Win32.Ramnit.K@37eb7u
F-SecureMalware.W32/Ramnit.C
DrWebWin32.Rmnet.8
VIPREVirus.Win32.Ramnit.b (v)
Invinceaheuristic
SentinelOneDFI – Malicious PE
SophosW32/Ramnit-A
APEXMalicious
CyrenW32/Ramnit.B!Generic
JiangminWin32/IRCNite.wi
AviraW32/Ramnit.C
MAXmalware (ai score=85)
Antiy-AVLVirus/Win32.Nimnul.a
KingsoftWin32.Ramnit.lx.30720
ArcabitWin32.Ramnit.N
AhnLab-V3Win32/Ramnit.J
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.P
CynetMalicious (score: 100)
TotalDefenseWin32/Ramnit.C
McAfeeW32/Ramnit.a
TACHYONVirus/W32.Ramnit
VBA32Virus.Win32.Nimnul.b
PandaW32/Nimnul.A
ZonerTrojan.Win32.Ramnit.22016
FortinetW32/Ramnit.A
TencentVirus.Win32.Nimnul.e
YandexWin32.Nimnul.Gen.2
IkarusVirus.Win32.Nimnul
GDataWin32.Virus.Nimnul.A
AVGWin32:RmnDrp
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Virus.Win32.Ramnit.A

How to remove Virus:Win32/Ramnit.P?

Virus:Win32/Ramnit.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment