Malware

About “Win32/RanumBot.X” infection

Malware Removal

The Win32/RanumBot.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RanumBot.X virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/RanumBot.X?


File Info:

crc32: C1866A32
md5: bd4b03e6127a34ecab890f6eb1546634
name: wupxarch.exe
sha1: 010fe245eaaafa90ed7939a85134ebf6866b40b9
sha256: 52c8cff981e5d541e4b2930a4a5e0b0a495d62c8237e91538d94c03a048dd51d
sha512: eb57236b6298b2989dea27720bf273b3a9538636b500b9309816571f885549d6841cc7ecc38bc204545d929ae5313de394661e81022718b80cca2e341929ade9
ssdeep: 24576:+S7tE6l9tlzRA9mSCctL0J/rlZqTdU6Dj63pn5TjJyA7Dr0KnKcsL/q7VuyRIFp:+mf9TklztL0JlMa6D+nRwqK3qYpp
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/RanumBot.X also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.43457462
FireEyeGeneric.mg.bd4b03e6127a34ec
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXAA-AA!BD4B03E6127A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.RanumBot.4!c
SangforMalware
K7AntiVirusTrojan ( 005621491 )
BitDefenderTrojan.GenericKD.43457462
K7GWTrojan ( 005621491 )
TrendMicroTROJ_GEN.R002C0PG920
SymantecTrojan Horse
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.43457462
KasperskyTrojan.Win32.Staser.dvli
AlibabaTrojan:Win32/Staser.4491560f
NANO-AntivirusTrojan.Win32.RanumBot.hibvqs
ViRobotTrojan.Win32.Z.Ursu.1983488.A
Ad-AwareTrojan.GenericKD.43457462
SophosMal/Generic-S
F-SecureTrojan.TR/SpyBot.zjpuq
DrWebTrojan.SpyBot.958
ZillyaTrojan.Staser.Win32.9242
Invinceaheuristic
MaxSecureTrojan.Malware.300983.susgen
EmsisoftTrojan.GenericKD.43457462 (B)
IkarusTrojan.Win32.Ranumbot
CyrenW32/Trojan.WLPC-3394
JiangminTrojan.Poebot.e
AviraTR/SpyBot.zjpuq
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Staser
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2971BB6
ZoneAlarmTrojan.Win32.Staser.dvli
MicrosoftTrojan:Win32/Ymacco.AA52
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Agent.C4058277
ALYacTrojan.GenericKD.43457462
VBA32TrojanSpyBot
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/RanumBot.X
TrendMicro-HouseCallTROJ_GEN.R002C0PG920
RisingTrojan.RanumBot!8.112AC (CLOUD)
SentinelOneDFI – Malicious PE
FortinetW32/RanumBot.X!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM11.1.618C.Malware.Gen

How to remove Win32/RanumBot.X?

Win32/RanumBot.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment