Trojan

Should I remove “TrojanDownloader:Win32/Renos.DS”?

Malware Removal

The TrojanDownloader:Win32/Renos.DS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Renos.DS virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Renos.DS?


File Info:

name: 9B88E1E881F7365077B2.mlw
path: /opt/CAPEv2/storage/binaries/d0aa1a366e8035c9318f3052c4ee23a75f77ef98e2d341ab699f842645606649
crc32: B86747FD
md5: 9b88e1e881f7365077b24f3fde037f06
sha1: bef7c979a5739366ca755b8a42004f00608afc74
sha256: d0aa1a366e8035c9318f3052c4ee23a75f77ef98e2d341ab699f842645606649
sha512: 5cae5b5b5d2ee29c38fd9a879f27014813148549724d41742233a93ad5a411130b077b5e4be3f150ef29ef5a5eb6734338a458d1012485b5bcc28e2eb44cf769
ssdeep: 768:6NJlNb/ija+1Iidqj9X8C6Py5LAb6FnEHU+dWwpE86Z8hDWc860ysg45nW6b/1x6:6NJ7KqBX8C6VyE0+lhp34M6bNWn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6135B17F5D0CA37D032C8F58C16C594BAB77A302D3168AB39AE5FCCDEA81C2651D24A
sha3_384: cefe7540b3350bd1031185662d5dd7284333a8d66cd98e2e015fa85aef5fada4148c829bca24e4dab66f63b09b024cdf
ep_bytes: 558bec83c4f0535657b8989a4000e871
timestamp: 2008-07-24 06:59:00

Version Info:

0: [No Data]

TrojanDownloader:Win32/Renos.DS also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.322300
ClamAVWin.Trojan.Delf-23605
McAfeeFakeAV-DZ
Cylanceunsafe
VIPREGen:Variant.Zusy.322300
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.881f73
VirITTrojan.Win32.Generic.AYBS
CyrenW32/Trojan.BCEA-6336
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Delf.OHL
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Delf.fei
BitDefenderGen:Variant.Zusy.322300
NANO-AntivirusTrojan.Win32.Delf.cxbdrn
ViRobotTrojan.Win32.Delf.44578
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13acba97
EmsisoftGen:Variant.Zusy.322300 (B)
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoad.22946
ZillyaTrojan.Delf.Win32.26117
McAfee-GW-EditionFakeAV-DZ
FireEyeGeneric.mg.9b88e1e881f73650
GDataGen:Variant.Zusy.322300
JiangminTrojanDownloader.Agent.aink
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.Delf
XcitiumTrojWare.Win32.Downloader.Ranos.~BAAB@fohe
ArcabitTrojan.Zusy.D4EAFC
ZoneAlarmTrojan.Win32.Delf.fei
MicrosoftTrojanDownloader:Win32/Renos.DS
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.C118681
BitDefenderThetaAI:Packer.1C0034C81F
ALYacGen:Variant.Zusy.322300
MAXmalware (ai score=88)
VBA32Trojan.Delf
RisingTrojan.Win32.Undef.qqm (CLASSIC)
YandexTrojan.GenAsa!iL/DENNjQT8
IkarusTrojan-Downloader.Win32.FraudLoad
MaxSecureTrojan.Malware.772809.susgen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove TrojanDownloader:Win32/Renos.DS?

TrojanDownloader:Win32/Renos.DS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment