Malware

How to remove “Renos.38 (B)”?

Malware Removal

The Renos.38 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Renos.38 (B) virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Renos.38 (B)?


File Info:

crc32: 8CB9B060
md5: 9d6722a4441bc3462e138ab6f75853e5
name: 9D6722A4441BC3462E138AB6F75853E5.mlw
sha1: c2c754e92c29da6b658b19ac5a146a5afb138ea3
sha256: 08ecdcae44caaf283612f9ac8bca279216a5f0070c013a6247e147852940ccd5
sha512: ca2269da00073115432fcaa5ddd35b2a30f95cb6e29492c60ad933091e07f3543cc8f30dde82c9b6a99b3754b5237bc04e69a8c282872e8a028d24d87c607e6b
ssdeep: 1536:hdayf+8Pbjnlxk+HhrRs7TOf37448anfcICx+C/kMIkzxMPIG3:fayf+ybnk+BrSfCX7fc9xXPVzxMZ3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Renos.38 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005588651 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29417
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Nemty
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Nemty.dad74d3b
K7GWTrojan ( 005588651 )
Cybereasonmalicious.4441bc
ESET-NOD32a variant of Win32/Filecoder.Nemty.A
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Renos.38
NANO-AntivirusTrojan.Win32.Filecoder.fyxxjt
ViRobotTrojan.Win32.Nemty.91648
MicroWorld-eScanGen:Variant.Renos.38
TencentWin32.Trojan.Filecoder.Hvsx
Ad-AwareGen:Variant.Renos.38
SophosML/PE-A + Troj/Nemty-A
BitDefenderThetaAI:Packer.6F13B3CF1E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.NEMTY.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.9d6722a4441bc346
EmsisoftGen:Variant.Renos.38 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dyngm
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftRansom:Win32/Nemty.D
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Renos.38
AhnLab-V3Trojan/Win32.Nemty.C3467022
Acronissuspicious
McAfeeRansom-Nemty!9D6722A4441B
MAXmalware (ai score=85)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Nemty
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.NEMTY.SMTH
RisingRansom.Agent!8.6B7 (CLOUD)
YandexTrojan.GenAsa!THWuS6ZoOaY
IkarusTrojan-Ransom.Nemty
FortinetW32/Generic.AP.2FD690!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDownloader.Generic.HwoCPrcA

How to remove Renos.38 (B)?

Renos.38 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment