Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Feb 03, 2011 | Updated Sep 15, 2017

Trojan:Win32/Ramnit

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Windows Defender detects and removes this threat.

This threat  can steal your sensitive information, such as your saved FTP credentials and web browser cookies.

It spreads via infected removable drives, such as USB flash drives.

See the Win32/Ramnit family description for more information.

Use the following free Microsoft software to detect and remove this threat:

You should also run a full scan. A full scan might find other, hidden malware.

Advanced troubleshooting

To restore your PC, you might need to download and run Windows Defender Offline. See our advanced troubleshooting page for more help.

Protect your sensitive information

This threat tries to steal your sensitive and confidential information. If you think your information has been stolen, see:

You should change your passwords after you've removed this threat:

Get more help

You can also ask for help from other PC users at the Microsoft virus and malware community.

If you’re using Windows XP, see our Windows XP end of support page.

Follow us