Malware

How to remove “WinGo/RanumBot.AV”?

Malware Removal

The WinGo/RanumBot.AV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/RanumBot.AV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine WinGo/RanumBot.AV?


File Info:

name: 630D3A91E01865AF6BBC.mlw
path: /opt/CAPEv2/storage/binaries/d5a5deb53688c90cdeba54bcf817bafcc72f6684fd7fcbf0cb9ad26a060f8fe9
crc32: 4A1AE979
md5: 630d3a91e01865af6bbcf80478fcd5e6
sha1: 3c5cbf080cd2f0e6045d15db85c6e11aea978bb2
sha256: d5a5deb53688c90cdeba54bcf817bafcc72f6684fd7fcbf0cb9ad26a060f8fe9
sha512: a3861f517c80a5f50f03b4a6e59288735e03a81f11eacdfa63fdbf429de17ed3828612ca2019613133c48f3e34e649e9d65aa5ea90aa692b9c08fba2200c2ba7
ssdeep: 98304:YiDHVidKXx53yhFZAkO26hafSnw5E5uGS+Dv3:b1QKh53yh9fgDuGz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16716334176A86333F6F342728AB8A3D10EFB78837734749E4155056A4D387E1E96E32B
sha3_384: 3725705d89c340f702704711ac81af818e303bd56b7f668125c1555a19d4db8e6cd101486da90e4377387a9b2fd02441
ep_bytes: e812180000e989feffff8bff558bec81
timestamp: 2023-06-27 22:39:18

Version Info:

FileVersion: 94.6.17.36
ProductVersion: 57.27.97.50
InternalName: Stupido
LegalCopyright: Silent news
CompanyName: Torque
Translation: 0x377b 0x02fc

WinGo/RanumBot.AV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Windigo.l!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.630d3a91e01865af
SkyhighBehavesLike.Win32.Lockbit.rc
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00589d2d1 )
K7GWTrojan ( 00589d2d1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32WinGo/RanumBot.AV
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Windigo.gen
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
SophosTroj/Krypt-ADH
SentinelOneStatic AI – Malicious PE
GDataWin32.Packed.Kryptik.WGB0MR
VaristW32/Kryptik.LLU.gen!Eldorado
AviraTR/Crypt.Agent.envrp
Kingsoftmalware.kb.a.1000
ZoneAlarmHEUR:Trojan-Spy.Win32.Windigo.gen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R611970
McAfeeArtemis!630D3A91E018
VBA32BScope.TrojanDownloader.Ajent
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@AI.100 (RDML:dVkKbGdT/yEoA6wu5na28w)
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.36680.@x1@aaUBnfmi
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove WinGo/RanumBot.AV?

WinGo/RanumBot.AV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment