Trojan

About “TrojanDownloader:Win32/Renos.GW” infection

Malware Removal

The TrojanDownloader:Win32/Renos.GW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Renos.GW virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Renos.GW?


File Info:

name: 36FF9E1A03AC2902CD12.mlw
path: /opt/CAPEv2/storage/binaries/871357d68fada12059eba4ebd097a3c0050624879a631270da74d09a10b86d99
crc32: 8422F30A
md5: 36ff9e1a03ac2902cd1278ad30481ba9
sha1: 7f2898a0745499668a1d3b7a29650c4e0015fa27
sha256: 871357d68fada12059eba4ebd097a3c0050624879a631270da74d09a10b86d99
sha512: 5d3bfc2c9ad0f3f07b6d832ee39a20615191b8113bfc6020c576565d8851cca0b34cbd4bdf1495cbe5cac5d94d71b7c0662e0db12fa475276460a878360ed13a
ssdeep: 3072:wDh380BMyJ1sizw4LiFjv7rveixfuHgmT0LeahNcnmhCGs:V0bPzw4Wjv7TzAHRZahNym0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AE301566CF391B1C82945B003F6527569B794E29B03823FED90CB4B9A36D06AB33D6C
sha3_384: cfb9e299262a5fce129e7c9467cb7ee3b841b3853887b8777871e42b11d432cacbd2d11b225f12f904a2793497d85f9d
ep_bytes: 558bec6aff6870524000687c42400064
timestamp: 2009-01-01 13:42:41

Version Info:

0: [No Data]

TrojanDownloader:Win32/Renos.GW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Nekill.lmvG
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.429034
FireEyeGeneric.mg.36ff9e1a03ac2902
SkyhighBehavesLike.Win32.Dropper.cc
McAfeeDownloader-AQW.g
Cylanceunsafe
ZillyaTrojan.Agent.Win32.13024
SangforDownloader.Win32.FakeAlert.V6ox
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/FakeAlert.9c68b089
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.a03ac2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.FakeAlert.VB
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT.AHXU
ClamAVWin.Trojan.Agent-128892
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.429034
NANO-AntivirusTrojan.Win32.Agent.qdgx
ViRobotTrojan.Win32.Agent.151556
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b64dd6
EmsisoftGen:Variant.Zusy.429034 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.MulDrop3.51717
VIPREGen:Variant.Zusy.429034
TrendMicroTROJ_AGENT.AHXU
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Agent
JiangminTrojan/Agent.bqfu
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/FakeAlert.DF.gen!Eldorado
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojanDownloader:Win32/Renos.GW
XcitiumTrojWare.Win32.Trojan.BHO.~GJ@1qmdj
ArcabitTrojan.Zusy.D68BEA
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.429034
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Agent.R27620
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Zusy.429034
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingTrojan.DL.Win32.Mnless.bzh (CLASSIC)
YandexTrojan.GenAsa!MjxOivjdGRs
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.972260.susgen
FortinetW32/Generic.AC.1FD769!tr
BitDefenderThetaAI:Packer.B2991D761E
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:Win/FakeAlert.VB

How to remove TrojanDownloader:Win32/Renos.GW?

TrojanDownloader:Win32/Renos.GW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment