Home Malware Programs Trojans Ramnit.D

Ramnit.D

Posted: June 6, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 145
First Seen: June 6, 2011
OS(es) Affected: Windows

W32/Ramnit.D is a dangerous Trojan horse that is known for its ability to download and install other malware onto the infected system. Most times other malware ported by W32/Ramnit.D is done without any indication to the PC user. W32/Ramnit.D may also allow a remote attacker to gain access where data stored on the hard drive could be stolen. It is important to eliminate the threat of W32/Ramnit.D by using an antispyware tool for complete removal of this vicious parasite.

Aliases

TROJ_SPNR.06DQ12 [TrendMicro]Troj/ZXC-G [Sophos]Trojan.Win32.Lebag.akl [Kaspersky]Trojan.Kazy-816 [ClamAV]Generic Trojan [Panda]Generic21.BUA [AVG]W32/Lebag.CQN!tr [Fortinet]Trojan.SuspectCRC [Ikarus]Win-Trojan/Ramnit.108544 [AhnLab-V3]Trojan/Win32.Lebag.gen [Antiy-AVL]W32/Ramnit-BL [Sophos]Heuristic.BehavesLike.Win32.Suspicious-BAY.K [McAfee-GW-Edition]Trojan.MulDrop1.64009 [DrWeb]MalCrypt.Indus! [Comodo]Trojan.Generic.7492779 [BitDefender]
More aliases (221)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\TEMP\R66v.exe File name: R66v.exe
Size: 208.21 KB (208219 bytes)
MD5: 342d865e83df9b760c70dedb7c60167e
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: June 6, 2011
%TEMP%\wpbt0.dll File name: wpbt0.dll
Size: 114 KB (114008 bytes)
MD5: 3ff1bbcc5cdf446fb321baebb0e0a1ba
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: January 24, 2012
%SystemDrive%\Documents and Settings\Wicky\Start Menu\Programs\Startup\mlugevyg.exe File name: mlugevyg.exe
Size: 79.77 KB (79770 bytes)
MD5: a7d104615cae890f0b2d0c52de1015b0
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Wicky\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 10, 2012
%USERPROFILE%\Local Settings\Application Data\hxljleyp\pedvveig.exe File name: pedvveig.exe
Size: 112.84 KB (112841 bytes)
MD5: bcc9bb9ac93fa2b7aa2f469921ce73a5
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\hxljleyp
Group: Malware file
Last Updated: October 27, 2011
%APPDATA%\msnl.exe File name: msnl.exe
Size: 71.8 KB (71805 bytes)
MD5: f61cb45f107cd0e231eba560a8651cea
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 7, 2011
%PROGRAMFILES%\Bonjour\mDNSResponder.exe File name: mDNSResponder.exe
Size: 349.47 KB (349472 bytes)
MD5: 7af4cbc61bc11dbbddb5a9470daaec21
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Bonjour
Group: Malware file
Last Updated: June 10, 2011
%PROGRAMFILES%\Avira\AntiVir Desktop\avguard.exe File name: avguard.exe
Size: 269.48 KB (269480 bytes)
MD5: 3b7a8ea1548a6ea9ab0fdcd9c7dbb1ca
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Avira\AntiVir Desktop
Group: Malware file
Last Updated: June 8, 2011
%USERPROFILE%\Start Menu\Programs\Startup\qcyscorq.exe File name: qcyscorq.exe
Size: 195.6 KB (195601 bytes)
MD5: ccc035796ca02835819656edd73f9e2b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: June 30, 2011
%USERPROFILE%\Local Settings\Application Data\rowlrbqp\aulxcbad.exe File name: aulxcbad.exe
Size: 119.61 KB (119617 bytes)
MD5: db258e57736dc7dbb7353bd431abd2b2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\rowlrbqp
Group: Malware file
Last Updated: January 10, 2012

Related Posts

Loading...