Malware

About “Win32/Redyms.AF” infection

Malware Removal

The Win32/Redyms.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Redyms.AF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Redyms.AF?


File Info:

name: E86B0D0B47604E89ABA2.mlw
path: /opt/CAPEv2/storage/binaries/6c69fb4f2470fbdada7c0812a84e9ceaf6726f496408a7687fc1e69fa9a5eb10
crc32: B8BAD463
md5: e86b0d0b47604e89aba2b97ddfd155c4
sha1: 2b380c4c2da67b405663aee64422fa77d57bda77
sha256: 6c69fb4f2470fbdada7c0812a84e9ceaf6726f496408a7687fc1e69fa9a5eb10
sha512: 9987ed1acae21fe47ea323a2f7067cf2a0ce1a462aa1c016ef8f7dbe5592a83d25586c6beab0d0c743c11784fec9eb298c26a7e7de3047deb03e0a1bd1a5a80f
ssdeep: 6144:dm1O0r8LmhuBxZC2lN+UP2IfHSFoyti/li6Pelq+mdOCeTay:nLLnJP2miu+BTa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18964E844B9D26B62FC81D6FCC736BB738D2BC9762E05619382E16FCD01242E641E5DE2
sha3_384: 00b86d325c4a72783709280c5a4e0a6644e4fb2b897be8a6d37da4cd002e207a6c3f87a7cf7d7bbd6957198d2cc52d21
ep_bytes: 558bec83ec445657c745c8a1664871a1
timestamp: 2013-12-29 19:33:06

Version Info:

0: [No Data]

Win32/Redyms.AF also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.e86b0d0b47604e89
SkyhighBehavesLike.Win32.PWSZbot.fh
McAfeeTrojan-FEAY!E86B0D0B4760
Cylanceunsafe
ZillyaTrojan.Redyms.Win32.378
CrowdStrikewin/malicious_confidence_90% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITTrojan.Win32.Agent.EHE
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Redyms.AF
APEXMalicious
TrendMicro-HouseCallTROJ_SPNR.06AE14
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GuraqVM.csfgzy
AvastWin32:FiestaEK-L [Trj]
TencentWin32.Trojan.Generic.Dkjl
F-SecureHeuristic.HEUR/AGEN.1372825
DrWebBackDoor.Finder.11
TrendMicroTROJ_SPNR.06AE14
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusBackdoor.Win32.Tedroo
JiangminTrojan/Generic.basno
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraHEUR/AGEN.1372825
VaristW32/Redyms.A.gen!Eldorado
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Ramdo.A
XcitiumMalware@#6f3dviol2ob9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.Agent.LC605O
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Symmi.R93200
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Agent.JIQ
RisingMalware.Undefined!8.C (TFE:3:msa2nzx9eoV)
YandexTrojan.Agent!IyEfH/JUQe4
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Redyms.AF!tr
AVGWin32:FiestaEK-L [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.Ramdo.cc437bd6

How to remove Win32/Redyms.AF?

Win32/Redyms.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment