Malware

About “WinGo/RanumBot.U” infection

Malware Removal

The WinGo/RanumBot.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/RanumBot.U virus can do?

    How to determine WinGo/RanumBot.U?

    
    

    File Info:

    crc32: 307D5E26
    md5: 3aedb84a098c37df5bf191c81bc49311
    name: 3AEDB84A098C37DF5BF191C81BC49311.mlw
    sha1: 99da32024fedf8ddcd2bed2dec4271936aacd423
    sha256: 1f05af488c46c1848d57ed3e16c6cb6814d3cf8ed995ce5d38482a2c5fb749e5
    sha512: 540b5d0dddab75f8a2338734d6a08afeefb61c66a94e02f4cdd7a6f282c45f799a6391bbed2d8905e4de6b104180edb72c2387af713526c4a0cb59bb4287f63a
    ssdeep: 49152:zOrazsN3G1K8g2EgVGe/nyh2ULEtcCt0UjCCWXdSCGYuoCWyquAb7/i:zOrao8K8sgg4ULEft0UaCC/i
    type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

    Version Info:

    0: [No Data]

    WinGo/RanumBot.U also known as:

    K7AntiVirusTrojan ( 00577d6f1 )
    LionicTrojan.Win32.Windigo.m!c
    CynetMalicious (score: 100)
    ALYacTrojan.GenericKD.47311189
    CylanceUnsafe
    SangforBackdoor.Win32.Windigo.g
    CrowdStrikewin/malicious_confidence_60% (W)
    AlibabaBackdoor:Win32/Windigo.fe2f16b3
    K7GWTrojan ( 00577d6f1 )
    CyrenW32/RanumBot.P.gen!Eldorado
    SymantecML.Attribute.HighConfidence
    ESET-NOD32a variant of WinGo/RanumBot.U
    APEXMalicious
    AvastWin32:Trojan-gen
    KasperskyBackdoor.Win32.Windigo.g
    BitDefenderTrojan.GenericKD.47311189
    MicroWorld-eScanTrojan.GenericKD.47311189
    Ad-AwareTrojan.GenericKD.47311189
    SophosMal/Generic-S
    F-SecureHeuristic.HEUR/AGEN.1141949
    BitDefenderThetaGen:NN.ZexaF.34236.@xW@a4uFkxm
    McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
    FireEyeGeneric.mg.3aedb84a098c37df
    EmsisoftTrojan.GenericKD.47311189 (B)
    SentinelOneStatic AI – Malicious PE
    JiangminBackdoor.MSIL.culd
    WebrootW32.Trojan.Gen
    AviraHEUR/AGEN.1141949
    KingsoftWin32.Hack.Windigo.g.(kcloud)
    MicrosoftTrojan:Win32/Sabsik.FL.B!ml
    ArcabitTrojan.Generic.D2D1E955
    ZoneAlarmBackdoor.Win32.Windigo.g
    GDataTrojan.GenericKD.47311189
    AhnLab-V3Malware/Win32.Generic.C3155694
    McAfeeArtemis!3AEDB84A098C
    MAXmalware (ai score=80)
    MalwarebytesMalware.Heuristic.1006
    RisingTrojan.Generic@ML.100 (RDMK:dt5zNfSJn044v94xz2fBVw)
    IkarusTrojan.WinGo.Ranumbot
    FortinetW32/RanumBot.U!tr
    AVGWin32:Trojan-gen

    How to remove WinGo/RanumBot.U?

    WinGo/RanumBot.U removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment