Home Malware Programs Trojans W32/Ramnit.E

W32/Ramnit.E

Posted: September 21, 2011

Threat Metric

Ranking: 10,877
Threat Level: 9/10
Infected PCs: 663
First Seen: September 21, 2011
Last Seen: October 12, 2023
OS(es) Affected: Windows

W32/Ramnit.E is a malicious Trojan, which connects itself to a remote server and operates according to instructions received. W32/Ramnit.E propagates with .exe and .html files. W32/Ramnit.E creates a hidden process in a web browser avoiding the firewall. W32/Ramnit.E can also download and install additional malware infections. Trojan Ramnit.E may slow your computer and result in PC system errors. Trojan Ramnit.E may hijack your homepage and create fake security alerts. Trojan Ramnit.E may change system settings and disable Windows features. Remove W32/Ramnit.E immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\56493.exe File name: %Temp%\56493.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\8gmsed-bd.exe File name: %Temp%\8gmsed-bd.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\a75wef8e0e7.exe File name: %Temp%\a75wef8e0e7.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\ae0965a7157cd.exe File name: %Temp%\ae0965a7157cd.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\al3erfa3.exe File name: %Temp%\al3erfa3.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\02c9c3c35bdx5.exe File name: %Temp%\02c9c3c35bdx5.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\17dkf.exe File name: %Temp%\17dkf.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\1iowieoo.exe File name: %Temp%\1iowieoo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\2010yo.exe File name: %Temp%\2010yo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\472a10e2ebxd9.exe File name: %Temp%\472a10e2ebxd9.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\aler3fa.exe File name: %Temp%\aler3fa.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\alerfa.exe File name: %Temp%\alerfa.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\alerfa2.exe File name: %Temp%\alerfa2.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\alerfa322.exe File name: %Temp%\alerfa322.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\aqfitrlxi2.exe File name: %Temp%\aqfitrlxi2.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Win32/ramnit.gen!A
Loading...