Home Malware Programs Worms W32.Ramnit.B

W32.Ramnit.B

Posted: November 16, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 61
First Seen: December 27, 2010
OS(es) Affected: Windows

W32.Ramnit.B is a computer worm that spreads on removable USB drives. W32.Ramnit.B does this by creating an Autorun.Inf file on the root of each drive inserted to the compromised machine. W32.Ramnit.B will run automatically if the affected drive is accessed, causing the targeted system endless problems. Remove W32.Ramnit.B from the system immediately using a genuine malware remover.

Aliases

Trj/Passtealer.MA [Panda]BackDoor.Generic13.YDY [AVG]W32/IRCNite.BLP!tr.bdr [Fortinet]Backdoor.Win32.IRCNite [Ikarus]Win-Trojan/Injector.65966 [AhnLab-V3]Worm:Win32/Ramnit.B [Microsoft]Backdoor/Win32.IRCNite.gen [Antiy-AVL]BDS/IRCNite.cfo [AntiVir]Win32.HLLW.Autoruner.38266 [DrWeb]TrojWare.Win32.Inject.~pe [Comodo]W32/Autorun-BLP [Sophos]Trojan.Generic.KD.88699 [BitDefender]Backdoor.Win32.IRCNite.cfo [Kaspersky]Win32:Malware-gen [Avast]W32.Ramnit [Symantec]
More aliases (30)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Start Menu\Programs\Startup\hjlcoroj.exe File name: hjlcoroj.exe
Size: 65.96 KB (65966 bytes)
MD5: 31c51d3b6c637ff66bfb84c5c1bcdbad
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 28, 2010
Loading...