Trojan

TrojanDownloader:Win32/Renos.PC (file analysis)

Malware Removal

The TrojanDownloader:Win32/Renos.PC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Renos.PC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Renos.PC?


File Info:

name: B3C24D5B7663CF9A3D93.mlw
path: /opt/CAPEv2/storage/binaries/7f1ca8ef0f54f00450e034bdbbe9ccb455a8b90dc960c3c872b0b5c93b054e30
crc32: D7274609
md5: b3c24d5b7663cf9a3d9385f0334259e6
sha1: 01e2ba5be5fa16160f77d03dd55aade72407f3b3
sha256: 7f1ca8ef0f54f00450e034bdbbe9ccb455a8b90dc960c3c872b0b5c93b054e30
sha512: fc3dd2b542259f0b1fd34913559bba3d05c6e1daa4cce07b8e54dc12a4ea8f21a678cdc7efac5621e63691079820b896ce0c080099f006a5cf5d8b5f518be1b0
ssdeep: 3072:OG43VzZ/Ifgzk+Zr5zbugfar6LHqnT6w8nQgNJ5CCH6e6lSMu8mz1Hj0:Ov3VzzrZr5+XQKTT8QgNJY5Bwb8mz1w
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19104010C77284144FDF31E3870FE1D96033775E92BE5EBA30651349A5CAB0A5F960B16
sha3_384: 6fc743b7d3a19b4311986ed3395385341bf5bcd4e6ba0cdb7b3501e1828f5e2348e86d74bc3ee22eb7bf03350059b787
ep_bytes: 558bec83c4e8030dc8a902101b45ec01
timestamp: 2009-09-17 20:54:20

Version Info:

CompanyName: AVG Technologies CZ, s.r.o.
FileDescription: W AVG Alert Managerb0
FileVersion: 9.0.0.832
InternalName: 2av-gamx1.dll
LegalCopyright: Copyright © 2010 AVG Technologies CZ, s.r.o.s
OriginalFilename: 2av-gamx1.dll
ProductName: AVG Internet Security ky
ProductVersion: 9.0.0.832
PrivateBuild: Win32 Release_Unicode
SpecialBuild: Avg8VC8NJ_2010_0603_213001(832), SVNRev 132525 (/branches/release/avg90_sp3)
Translation: 0x0405 0x04b0

TrojanDownloader:Win32/Renos.PC also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.llHW
DrWebTrojan.DownLoader2.22348
MicroWorld-eScanGen:Variant.Renos.79
FireEyeGeneric.mg.b3c24d5b7663cf9a
CAT-QuickHealTrojan.Renos.LX
SkyhighBehavesLike.Win32.Dropper.cc
McAfeeDownloader-CEW.af
MalwarebytesMalware.AI.3388652707
ZillyaTrojan.FakeAV.Win32.52766
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f3cc1 )
AlibabaTrojanDownloader:Win32/FakeAlert.b5772962
K7GWTrojan-Downloader ( 0040f3cc1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36802.ku8@aeoBcOoi
VirITTrojan.Win32.Generic.CTV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.FakeAlert.ARF
APEXMalicious
TrendMicro-HouseCallTROJ_KRYPTIK.SM4
ClamAVWin.Trojan.Renos-2167
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Renos.79
NANO-AntivirusTrojan.Win32.Dwn.cqogj
AvastWin32:MalOb-EM [Cryp]
TencentMalware.Win32.Gencirc.115a5693
EmsisoftGen:Variant.Renos.79 (B)
F-SecureTrojan-Downloader:W32/Renos.GTQ
VIPREGen:Variant.Renos.79
TrendMicroTROJ_KRYPTIK.SM4
SophosMal/FakeAV-IZ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GDataGen:Variant.Renos.79
JiangminTrojan/Genome.allc
WebrootW32.Malware.Downloader
GoogleDetected
AviraTR/Dldr.Renos.PD.3
VaristW32/FakeAlert.MV.gen!Eldorado
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
XcitiumPacked.Win32.TDSS.~AA@1rhbt5
ArcabitTrojan.Renos.79
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Renos.PC
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Fakeav.177152.AX
VBA32TrojanDownloader.FakeAlert
ALYacGen:Variant.Renos.79
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Renos!1.649B (CLASSIC)
YandexTrojan.DL.FakeAlert!hD4wPoja8kY
IkarusTrojan-Downloader.Win32.Renos
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Krypt.QKV!tr
AVGWin32:MalOb-EM [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/FakeAlert.ARF

How to remove TrojanDownloader:Win32/Renos.PC?

TrojanDownloader:Win32/Renos.PC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment