Virus

What is “Renamer.Virus.FileInfector.DDS”?

Malware Removal

The Renamer.Virus.FileInfector.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Renamer.Virus.FileInfector.DDS virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Renamer.Virus.FileInfector.DDS?


File Info:

crc32: EB4A90E5
md5: 2b013de0884dc1f12dbb62c37d39bec3
name: 2B013DE0884DC1F12DBB62C37D39BEC3.mlw
sha1: 8acbf60309bb255e894e10ad26f41ccf69d47831
sha256: 93ebe41720bfbe1f282d46a5330380c2db99cf86ddd647a0415b2e6a7fe94d09
sha512: 45d8f801582539e385d8a76d4c9aacb27666e4e5f8a2a4ca4526cc9e717939c1f4e96030b6e56acc3749d46630f0108d1d90ee8cb25cbf741923169faa74b128
ssdeep: 12288:9rMIztyCK5x8CBmn+RrNbEyWYa0Ie1vUx9VA:7ZyCA8CBmn+RrNj9ay5IA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Renamer.Virus.FileInfector.DDS also known as:

BkavW32.WangpuiNWP.Trojan
K7AntiVirusTrojan ( 000c8b551 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.58276
CynetMalicious (score: 100)
CAT-QuickHealW32.Grenam.A9
ALYacTrojan.GenericKD.45649623
CylanceUnsafe
ZillyaWorm.Delf.Win32.869
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Grenam.371
K7GWTrojan ( 004d4f8e1 )
Cybereasonmalicious.0884dc
BaiduWin32.Worm.Delf.bi
CyrenW32/A-2f9e86a4!Eldorado
SymantecW32.Tapin
ESET-NOD32Win32/Delf.NRJ
ZonerTrojan.Win32.87681
APEXMalicious
TotalDefenseWin32/HLLO.Grenam.A
AvastWin32:Renamer-F [Trj]
ClamAVWin.Virus.Gnamer-1
KasperskyVirus.Win32.Renamer.j
BitDefenderTrojan.GenericKD.45649623
NANO-AntivirusTrojan.Win32.Renamer.lnwkz
ViRobotWin32.Renamer.A
MicroWorld-eScanTrojan.GenericKD.45649623
TencentTrojan.Win32.Renamer.ttk
Ad-AwareTrojan.GenericKD.45649623
SophosML/PE-A + W32/Renamer-K
ComodoWorm.Win32.Delf.nj@4ri78u
BitDefenderThetaGen:NN.ZelphiF.34608.GKW@aeXOH5di
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.GRENAM.SM
McAfee-GW-EditionBehavesLike.Win32.Gnamer.hh
FireEyeGeneric.mg.2b013de0884dc1f1
EmsisoftTrojan.GenericKD.45649623 (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Renamer.A
MicrosoftVirus:Win32/Grenam.A
GridinsoftVirus.Win32.Grenam.sb!s1
ArcabitTrojan.Generic.D2B88ED7
ZoneAlarmVirus.Win32.Renamer.j
GDataTrojan.GenericKD.45649623
TACHYONWorm/W32.DP-Renamer.534016
AhnLab-V3Trojan/Win32.Renamer.R54474
Acronissuspicious
McAfeeW32/Gnamer
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
MalwarebytesRenamer.Virus.FileInfector.DDS
PandaTrj/Renamer.H
TrendMicro-HouseCallTrojan.Win32.GRENAM.SM
RisingTrojan.Win32.Renamer.g (RDMK:cmRtazrnzXKS+KWDCMnh2LQYcFvB)
YandexTrojan.GenAsa!bFkr50Cc7zI
IkarusDropper.Patched
MaxSecureVirus.W32.Renamer.J
FortinetW32/Renamer.BQT!tr
AVGWin32:Renamer-F [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM05.1.D82F.Malware.Gen

How to remove Renamer.Virus.FileInfector.DDS?

Renamer.Virus.FileInfector.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment