Worm

How to remove “Worm:Win32/Ramnit.A”?

Malware Removal

The Worm:Win32/Ramnit.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ramnit.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

fget-career.com
ddos.dnsnb8.net

How to determine Worm:Win32/Ramnit.A?


File Info:

crc32: 3B19B414
md5: 8378f314a9ab21602b5f66a63eeeca03
name: 8378F314A9AB21602B5F66A63EEECA03.mlw
sha1: 7bb1df3d027775714c7f0b03c9aec95f2bacde6e
sha256: 712902f16ad8e9570dc1e25dba5f4219f3fdd497d727f08dd98f1c6baa78335b
sha512: 1a760e84ca0b48ad66006b8e0372e91b41c85dc08b41aa0ebcc9a0e50b79f8fb05d10cd70f142f10a828b117fd6a2323e11698174624adc17ee57efb17bd70cf
ssdeep: 3072:rA2M9lmJM9lmJM9lmJM9lmkGCHN6ZCWYwMpuSNUQH:rAwhhh5i64J7u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Ramnit.A also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.VJadtre.3
FireEyeGeneric.mg.8378f314a9ab2160
McAfeeArtemis!8378F314A9AB
CylanceUnsafe
VIPRETrojan.Win32.Small.z (v)
SangforMalware
K7AntiVirusVirus ( 7000000b1 )
BitDefenderWin32.VJadtre.3
K7GWVirus ( 7000000b1 )
CrowdStrikewin/malicious_confidence_100% (D)
InvinceaML/PE-A + Mal/EncPk-ACE
BaiduWin32.Virus.Otwycal.d
CyrenW32/PatchLoad.E
SymantecW32.Wapomi.C!inf
APEXMalicious
ClamAVWin.Trojan.Downloader-64720
KasperskyVirus.Win32.Nimnul.f
NANO-AntivirusVirus.Win32.Ramnit.eslalb
AvastWin32:Ramnit-E
TencentVirus.Win32.Loader.aab
Ad-AwareWin32.VJadtre.3
EmsisoftWin32.VJadtre.3 (B)
ComodoVirus.Win32.Wali.KA@558nxg
F-SecureMalware.W32/Jadtre.B
DrWebBackDoor.Darkshell.246
TrendMicroTROJ_GEN.R06EC0DKI20
McAfee-GW-EditionBehavesLike.Win32.Virut.ch
SophosMal/EncPk-ACE
IkarusVirus.Ramnit
AviraW32/Jadtre.B
MAXmalware (ai score=81)
MicrosoftWorm:Win32/Ramnit.A
GridinsoftTrojan.Heur!.03012201
ArcabitWin32.VJadtre.3
ZoneAlarmVirus.Win32.Nimnul.f
GDataWin32.VJadtre.3
CynetMalicious (score: 100)
AhnLab-V3Win32/VJadtre.Gen
BitDefenderThetaAI:FileInfector.991137D00F
TACHYONVirus/W32.Ramnit.C
VBA32Heur.Trojan.Hlux
ZonerVirus.Win32.23755
ESET-NOD32a variant of Win32/Ramnit.BQ
TrendMicro-HouseCallTROJ_GEN.R06EC0DKI20
RisingVirus.Roue!1.9E10 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_66%
FortinetW32/Kudj.EC2B!tr
AVGWin32:Ramnit-E
Cybereasonmalicious.4a9ab2
Qihoo-360Virus.Win32.Agent.P

How to remove Worm:Win32/Ramnit.A?

Worm:Win32/Ramnit.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment