Malware

Should I remove “Renos.76”?

Malware Removal

The Renos.76 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Renos.76 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Renos.76?


File Info:

name: 23123CD952ECA390EEB1.mlw
path: /opt/CAPEv2/storage/binaries/d4465eef11c1d24819125caeb2985e169240f1a127c31f18b6783ca2569fca75
crc32: 2BAB0C27
md5: 23123cd952eca390eeb149a32ea5bae0
sha1: d65311151eee5fbd3cfaf0a63f8e9dd47f1a49cd
sha256: d4465eef11c1d24819125caeb2985e169240f1a127c31f18b6783ca2569fca75
sha512: 5505db7d66cdd8db031eb8fb2759a93b5ee28ec330b5270b310978e9fbed476ce6e03db68694684c2ea203a30670e94f849a1a1f265a5f8050753eeaf2645963
ssdeep: 1536:54QuTBtQgH3xo/96bg9/ugPu34xkPZhxIqFJowo5UHV7lpc:kZxoF6bgJluoyteoBl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C63F1BB8E4850B7C57E8336671E1A2408E6DD341A6DD20D30CD9E779BB14AE2F1B21D
sha3_384: e4a4d2f5debb2cd4df68443d60162b8897211db029e12d6c3b53b8327f846337c724a2020ecab888dd3cd7293e9fb269
ep_bytes: 60be000041008dbe0010ffff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Renos.76 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoader2.19892
MicroWorld-eScanGen:Variant.Renos.76
CAT-QuickHealTrojan.Renos.PG
SkyhighBehavesLike.Win32.HLLP.kc
McAfeeArtemis!23123CD952EC
MalwarebytesMalware.AI.2835734053
ZillyaTrojan.FakeAV.Win32.48553
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0021d5391 )
AlibabaTrojanDownloader:Win32/CodecPack.e6c28de9
K7GWTrojan ( 0021d5391 )
ArcabitTrojan.Renos.76
BitDefenderThetaAI:Packer.7B52C39521
VirITTrojan.Win32.Generic.CPGN
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.FakeAlert.BIN
APEXMalicious
TrendMicro-HouseCallTROJ_JORIK.SME2
ClamAVWin.Trojan.Renos-6272
KasperskyTrojan-Downloader.Win32.CodecPack.ampy
BitDefenderGen:Variant.Renos.76
NANO-AntivirusTrojan.Win32.Dwn.bwvik
SUPERAntiSpywareTrojan.Agent/Gen-FakeSec[Fraud]
AvastWin32:Downloader-GBD [Trj]
TencentMalware.Win32.Gencirc.115e2989
EmsisoftGen:Variant.Renos.76 (B)
F-SecureTrojan-Downloader:W32/Renos.GTZ
BaiduWin32.Trojan-Downloader.FakeAlert.ez
VIPREGen:Variant.Renos.76
TrendMicroTROJ_JORIK.SME2
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.23123cd952eca390
SophosMal/Agent-IE
IkarusTrojan-Downloader.Win32.CodecPack
JiangminTrojanDownloader.CodecPack.ckf
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/Remixt.G
VaristW32/FakeAlert.LJ.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.CodecPack
Kingsoftmalware.kb.b.972
XcitiumTrojWare.Win32.Renos.CJI@4pott4
MicrosoftProgram:Win32/Wacapew.C!ml
ViRobotTrojan.Win32.Downloader.67072.DC
ZoneAlarmTrojan-Downloader.Win32.CodecPack.ampy
GDataGen:Variant.Renos.76
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Renos.R2040
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Renos.76
Cylanceunsafe
PandaTrj/Renos.gen
RisingDownloader.Renos!8.1D0 (TFE:5:WCjOoQiYShC)
MAXmalware (ai score=100)
MaxSecureTrojan.CodecPack.Gen
FortinetW32/Codecpack.GB!tr
AVGWin32:Downloader-GBD [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/FakeAlert.BIN

How to remove Renos.76?

Renos.76 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment