Home / malwarePDF  


First posted on 15 February 2019.
Source: Microsoft

Aliases :

Virus:VBS/Ramnit.B is also known as VBS/Inor.DZ, HTML/Rce.Gen, HTML/Ramnit!generic, Trojan.Inor, Win32/Ramnit.A, Virus.VBS.Ramnit, HTML/Ramnit.A, W32/Cusmu.A, Dropper.Script.VBS.Fednu.a, VBS/Inor-AA, W32.Ramnit!html, VBS_INOR.EQ.

Explanation :

Virus:VBS/Ramnit.B is a detection for VBScript appended to HTML document files by Virus:Win32/Ramnit.B. When the infected HTML document is opened, it drops a copy of Worm:Win32/Ramnit.A and runs it. InstallationWhen an HTML document containing Virus:Win32/Ramnit.B is viewed or opened, it drops a copy of Worm:Win32/Ramnit.A as the following:  %TEMP%svchost.exe The dropped worm copy is then run. Additional InformationFor more information about Worm:Win32/Ramnit.A or Virus:Win32/Ramnit.B, see the descriptions elsewhere in the encyclopedia.  Analysis by Tim Liu

Last update 15 February 2019