Threat Database Trojans W32/Ramnit.E

W32/Ramnit.E

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 10,676
Threat Level: 90 % (High)
Infected Computers: 282
First Seen: September 21, 2011
Last Seen: July 27, 2023
OS(es) Affected: Windows

W32/Ramnit.E is a dangerous Trojan infection that infects Windows executable files and HTML files and tries to enable remote attackers gain access to the targeted PC. W32/Ramnit.E opens a back door by connecting to a remote server. With the help of this back door, remote attackers can instruct the compromised PC to download and execute files. W32/Ramnit.E drops some malicious files and makes other changes in the corrupted system. W32/Ramnit.E creates an invisible default web browser process and injects code to it. W32/Ramnit.E and back door functionality appears in the web browser process context, most likely in an attempt to bypass a firewall. Delete W32/Ramnit.E as quickly as possible.

File System Details

W32/Ramnit.E may create the following file(s):
# File Name Detections
1. %Temp%\a75wef8e0e7.exe
2. %Temp%\02c9c3c35bdx5.exe
3. %Temp%\2010yo.exe
4. %Temp%\alerfa.exe
5. %Temp%\aqfitrlxi2.exe
6. %Temp%\8gmsed-bd.exe
7. %Temp%\al3erfa3.exe
8. %Temp%\1iowieoo.exe
9. %Temp%\aler3fa.exe
10. %Temp%\alerfa322.exe
11. %Temp%\56493.exe
12. %Temp%\ae0965a7157cd.exe
13. %Temp%\17dkf.exe
14. %Temp%\472a10e2ebxd9.exe
15. %Temp%\alerfa2.exe

Registry Details

W32/Ramnit.E may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Win32/ramnit.gen!A

Trending

Most Viewed

Loading...