Trojan

TrojanDownloader:Win32/Renos.NL removal

Malware Removal

The TrojanDownloader:Win32/Renos.NL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Renos.NL virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Renos.NL?


File Info:

name: C78160FDD4711C56FE38.mlw
path: /opt/CAPEv2/storage/binaries/b2d93bf55e16877fbe2131cd920b97991b953464bf0527129db7d8f995f42b04
crc32: 9818F223
md5: c78160fdd4711c56fe381743ea732b98
sha1: 3fb20ac1177be9b8218b6c03792873b1f96fb474
sha256: b2d93bf55e16877fbe2131cd920b97991b953464bf0527129db7d8f995f42b04
sha512: 3d6c0f686dde897c3e0e48be8ac1c461542879eda801b538a208f39e67b334a85842b33dc579aaab75a699939ff6b28b6e3df7f7b683c85167cad7159244f369
ssdeep: 98304:kiH7eZZ24kmsYYh8FctCpMWztz434mbsJbo1Tr5kfuy/uH2eif7oCws:kiH7eZZImsQcYztETr5kfuyWHzifvP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1912633DAE540724EED7AA13D28F356B0022289B8CB85E36E1D55BFBD3B7E043357A444
sha3_384: 7bfcbad99f7ee78f1b0726f1388cfcaa0264009eeb8418b49ca1f41ef63d040b81d04683e02eac2053e3527e28a7c161
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

TrojanDownloader:Win32/Renos.NL also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
AVGWin32:Dropper-EZT [Drp]
DrWebTrojan.MulDrop2.59756
MicroWorld-eScanTrojan.GenericKD.65176810
FireEyeTrojan.GenericKD.65176810
ALYacTrojan.GenericKD.65176810
MalwarebytesGeneric.Trojan.Downloader.DDS
VIPRETrojan.GenericKD.65176810
SangforDownloader.Win32.Agent.Vb3h
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/Generic.da893b2d
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.6FACBB071E
VirITTrojan.Win32.Generic.AEEN
CyrenW32/Injector.A.gen!Eldorado
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.ALX
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Agent2-1982
KasperskyHEUR:Trojan-Spy.Win32.Agent.gen
BitDefenderTrojan.GenericKD.65176810
NANO-AntivirusTrojan.Win32.Agent.iihgp
AvastWin32:Dropper-EZT [Drp]
TencentWin32.Trojan-Downloader.Oader.Aplw
EmsisoftTrojan.GenericKD.65176810 (B)
F-SecureHeuristic.HEUR/AGEN.1345235
ZillyaDownloader.Agent.Win32.239588
TrendMicroTROJ_GEN.R002C0DI923
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
GDataTrojan.GenericKD.65176810
AviraHEUR/AGEN.1339543
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent.gen
XcitiumTrojWare.Win32.Agent2.cvzz@2zdvbv
ArcabitTrojan.Generic.D3E284EA
ZoneAlarmHEUR:Trojan-Spy.Win32.Agent.gen
MicrosoftTrojanDownloader:Win32/Renos.NL
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R10087
McAfeeArtemis!C78160FDD471
VBA32Trojan.Agent2
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DI923
RisingDownloader.Agent!8.B23 (TFE:5:CxCKeZ2vL3P)
YandexTrojan.GenAsa!rwOgzEW0nNM
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent2.EFI!tr.dldr
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Renos.NL?

TrojanDownloader:Win32/Renos.NL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment