Virus:VBS/Ramnit.gen!C is a VBScript appended to HTML documents. It spreads via HTML documents. It drops and runs another malware, which is detected as Trojan:Win32/Ramnit.A, which in turn infects HTML files.
When an infected HTML file detected as Virus:VBS/Ramnit.gen!C is opened, it drops and runs a copy of Trojan:Win32/Ramnit.A as the file ""%Temp%\svchost.exe".
Trojan:Win32/Ramnit.A infects DLL and EXE files, as well as HTML files. Infected HTML files are detected as Virus:VBS/Ramnit.gen!C. In certain cases, the infected HTML file may instead be detected as Virus:VBS/Ramnit.B.
Virus:VBS/Ramnit.gen!C appends random comments to its body in an attempt to avoid detection.