Malware

Renos.69 (B) removal tips

Malware Removal

The Renos.69 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Renos.69 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Likely virus infection of existing system binary
  • Attempts to identify installed analysis tools by a known file location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Renos.69 (B)?


File Info:

name: 99A3EB94D97CD2CE664C.mlw
path: /opt/CAPEv2/storage/binaries/4e938e2e965c0274da50c7359f7c6c19998d3c51d44f36d43f94b88ba56b1a3b
crc32: 46C12A7C
md5: 99a3eb94d97cd2ce664c306011060e5c
sha1: cab5b2767637e447bb795b9d9ed2dc77c4eea786
sha256: 4e938e2e965c0274da50c7359f7c6c19998d3c51d44f36d43f94b88ba56b1a3b
sha512: a260971fd597e7a6f09cc3267ca373cd2e5269d1e81d1dfafe60544ca0b0a8568a22f77899f93e83933d3db9fea9108bc65d6266d2cc18d81df31b8bf4f64928
ssdeep: 6144:71u7Im/PyY3tv7CVuSUmtos05uZvSZ+OLG:lgySXwVZvSZ+SG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B61413BC6B6D3516E03B883960C209138BF3E738791BD5DBBFB874DA8C117E8055849A
sha3_384: d8a8bdf4ad64fb80809c663d91353e479f01ab506048e37956d6027e5b64300c40793de63b7cdcbab28223822a3d13b0
ep_bytes: 60be006047008dbe00b0f8ff57eb0b90
timestamp: 2008-04-19 22:38:13

Version Info:

CompanyName: Krbmcaj Xoqlguu
FileDescription: Krbmcaj Obtosl Ksnguiqms
FileVersion: 70,75,16,54
InternalName: Krbmcaj
LegalCopyright: Copyright © Krbmcaj Xoqlguu 2002-2011
OriginalFilename: Krbmcaj.exe
ProductName: Krbmcaj Obtosl Ksnguiqms
ProductVersion: 49,46,126,20
Translation: 0x0409 0x04e4

Renos.69 (B) also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Generic.lh2q
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Renos.69
FireEyeGeneric.mg.99a3eb94d97cd2ce
CAT-QuickHealWorm.SlenfBot.Gen
McAfeeW32/Pinkslipbot.gen.af
CylanceUnsafe
VIPREBackdoor.Win32.IRCBot
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( f1000f011 )
AlibabaExploit:Win32/ShellCode.a2f31217
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.4d97cd
VirITTrojan.Win32.Generic.UIY
CyrenW32/Zbot.CN.gen!Eldorado
SymantecW32.IRCBot.NG
ESET-NOD32a variant of Win32/Kryptik.LDY
APEXMalicious
ClamAVWin.Trojan.Zbot-48555
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Renos.69
NANO-AntivirusTrojan.Win32.Kolab.ilppx
SUPERAntiSpywareTrojan.Agent/Gen-Pervaser
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Falsesign.Hvst
Ad-AwareGen:Variant.Renos.69
EmsisoftGen:Variant.Renos.69 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebBackDoor.IRC.Bot.750
ZillyaTrojan.FakeAV.Win32.70929
TrendMicroBKDR_IRCBOT.EV
McAfee-GW-EditionW32/Pinkslipbot.gen.af
SophosMal/Generic-R + Mal/FakeAV-IU
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Renos.69
JiangminTrojan/Generic.dbhh
WebrootW32.Worm.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2906DD
KingsoftWorm.Kolab.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/IRCbot
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZexaF.34212.mmLfaKmaQ9lc
ALYacGen:Variant.Renos.69
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallBKDR_IRCBOT.EV
RisingExploit.ShellCode!8.2A (CLOUD)
YandexTrojan.GenAsa!rTvAwvnOGnE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1698383.susgen
FortinetW32/Kryptik.NAS!tr
AVGWin32:DangerousSig [Trj]
PandaBck/Qbot.AO

How to remove Renos.69 (B)?

Renos.69 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment