My Bitdefender
  • 0 Shopping Cart

SHARE
THIS ON

Facebook Twitter Google Plus

Win32.Ramnit.G

VERY LOW
VERY LOW
112 KB
(Win32/Ramnit.A Win32.Rmnet VBS/Ramnit.B Trojan-Dropper.VBS.Exe2Vbs.b)

Symptoms

Presence of the file %TEMP%\svchost.exe

Running process %TEMP%\svchost.exe

Removal instructions:

Please let BitDefender disinfect your files.

Analyzed By

Robert Szasz, virus researcher

Technical Description:

This malware is a html file infected by a worm, with a visual basic script.

The script drops file %TEMP%\svchost.exe wich is detected as Win32.Ramnit.J, then executes this file.