Malware

BAT/Renamer.G removal

Malware Removal

The BAT/Renamer.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Renamer.G virus can do?

  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/Renamer.G?


File Info:

crc32: 179829EB
md5: af6d91121887f5bb0a85a06b1ded0db7
name: AF6D91121887F5BB0A85A06B1DED0DB7.mlw
sha1: 3dc746ae351adbaa192400a58c492c83dd7f4a10
sha256: 72ebc223bef1bf4cabad9c7eb6e520f0d93554f2807d4c8875be24dc3ab129a4
sha512: b8a2ccf5beded73df120077a91e01ec04cafb23007c56b8c2fda572aa115bd0a2a2a1f0d92df7f9e98a80130f0ae901d35acd6c145d36dcae6292e3e3837fe21
ssdeep: 3072:KNqyZWsMaaX+BQXlRAizi8tKCVBUTGSb4quBOM9xqoLWmjeuubcfltrgGc5cW0B:KNqiKQQvAUtK8UTGCO1tLWsf8cfvcl
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: FIFCOM Corp.
InternalName: FRS Ransomware
FileVersion: 23.33.33.33
CompanyName: FIFCOM Corp.
LegalTrademarks: FIFCOM Corp.
Comments: FRS Ransomware
ProductName: FRS Ransomware
ProductVersion: 23.33.33.33
FileDescription: FRS Ransomware
OriginalFilename: FRS.exe
Translation: 0x0409 0x04e4

BAT/Renamer.G also known as:

BkavHW32.Packed.
DrWebTrojan.MulDrop7.32995
MicroWorld-eScanTrojan.GenericKD.40168908
CMCVirus.Win32.Sality!O
CAT-QuickHealTrojan.Cossta
ALYacTrojan.Ransom.FRS
CylanceUnsafe
ZillyaTrojan.Cossta.Win32.10401
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Cossta.1a95c9bf
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroRansom_FRS.A
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Renamer.G
APEXMalicious
AvastOther:Malware-gen [Trj]
GDataTrojan.GenericKD.40168908
KasperskyTrojan.Win32.Cossta.alal
BitDefenderTrojan.GenericKD.40168908
NANO-AntivirusTrojan.Win32.Cossta.eysfqe
ViRobotTrojan.Win32.S.Ransom.276480
Ad-AwareTrojan.GenericKD.40168908
SophosMal/Generic-S
ComodoMalware@#ll9i348mqs6q
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.af6d91121887f5bb
EmsisoftTrojan.Encoder (A)
SentinelOneDFI – Malicious PE
Endgamemalicious (high confidence)
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_91%
Antiy-AVLTrojan/Win32.Cossta
MicrosoftTrojan:Win32/CryptInject
JiangminTrojan.Generic.utpa
ArcabitTrojan.Generic.D264EDCC
AegisLabTrojan.Win32.Cossta.4!c
ZoneAlarmTrojan.Win32.Cossta.alal
AhnLab-V3Trojan/Win32.Agent.C2426843
Acronissuspicious
McAfeeGeneric.dqa
MAXmalware (ai score=95)
VBA32Trojan.BAT.Renamer
PandaTrj/CI.A
TrendMicro-HouseCallRansom_FRS.A
TencentWin32.Trojan.Cossta.Lpll
YandexTrojan.Cossta!1c3Wp9rAms8
IkarusTrojan-Ransom.Rokku
MaxSecureTrojan.Malware.12136383.susgen
FortinetW32/Generic!tr
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.43e

How to remove BAT/Renamer.G?

BAT/Renamer.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment