W32.Ranetif
Aliases: N/A
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: North America
Removal: Easy
Platform: W32
Discovered: 28 Dec 2007
Damage: Low
Characteristics: W32.Ranetif is a worm, It opens a back door and infects files. A back door worm allows unauthorized remote attackers to access information on a remote computer. The backdoor worm is s slow infector. It causes low damage and is easy to remove using an updated antivirus software.
W32.Ranetif Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Ranetif from your computer.
More details about W32.Ranetif
The worm W32.Ranetif infects Windows systems. When the worm is executed, it creates the following files: INETINFO.EXE, scanip.txt, and svchost.exe. It then creates the following file on each drive so that it executes whenever the drive is accessed: autorun.inf. Afterwards, it creates a registry entry so that it executes whenever Windows starts. The worm may attempt to stop the following processes: regedit, rundll32, and mmc. It may also delete the associated files: regedit.exe, rundll32.exe, and mmc.exe. The worm attempts to gather IP addresses by opening a network connection and listening on TCP port 3310. The worm stores the gathered information in the file scanip.txt. Every three minutes, it scans drives for infection. The worm also opens a back door on the infected computer and waits for commands from a remote attacker.The W32.Ranetif program installs on a computer without the user’s knowledge and consent. It stays resident on the system’s background and launches at each computer start-up. The Trojan program is unknowingly downloaded by the user when accessing websites that are not secure.
Browse for more malware information
- W32.Ranetif
- W32.Rants.A@mm
- W32.Rarbeauty@mm
- W32.Reatle@mm
- W32.Recory@mm
- W32.Redlofs
- W32.Redlofwen
- W32.Redplut
- W32.Redzed@mm
- W32.Refaz
- W32.Refoav@mm
- W32.Reidana.A
- W32.Relfeer
- W32.Relnek.A
- W32.Remabl.Worm
- W32.Remadmin
- W32.Remadworm
- W32.Renama.A@mm
- W32.Renco@mm
- W32.Repad.Worm
- W32.Reploret
- W32.Resdoc
- W32.Resik.A
- W32.Rexli.A@mm
- W32.Reztrict@mm
- W32.Ridnu.B
- W32.Rinbot!gen
- W32.Rispif.A
- W32.Rokid
- W32.Ronoper.B@mm