Virus

Virus:Win32/Relnek.A malicious file

Malware Removal

The Virus:Win32/Relnek.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Relnek.A virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Virus:Win32/Relnek.A?


File Info:

name: 3477144AFD1441A6F10A.mlw
path: /opt/CAPEv2/storage/binaries/2f5eec5ec68a97416b1747967a3262531dec677a4463db86933194db7e8be95d
crc32: 1A466F8D
md5: 3477144afd1441a6f10a2957ef7660d6
sha1: 017c07bcc5a45f9c91b6ac6803eb8b810810da59
sha256: 2f5eec5ec68a97416b1747967a3262531dec677a4463db86933194db7e8be95d
sha512: cb9c7c13090703e47decc92e32640731a1729978c62b11b294dad33d6f6fc197243c1f910b975d293fcd6c208b64d58933edd7252d36065d5704589b3a76a7d2
ssdeep: 12288:EqOPajQUXXP8QvLWFx6MW5rippDC7ee1hpls4Ey+JA6z:EnajQEPnvg6FhWDC750
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E453A90F2C1C4B6D49711724DAADA3021A7BE588B7497DF615E370D9AB33C3247AF0A
sha3_384: 6e23c2b08d231cf73b0c4fef34afd3c45daf219e4499db2897cf4168db90287d601e310beba37ba32082b1752f15cf76
ep_bytes: 558bec505251535657baa0c20400b800
timestamp: 2006-08-28 07:08:09

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Help Viewer
FileVersion: 1.0.0.185
InternalName: Adobe Help Viewer
LegalCopyright: (C) 2006 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: ahv.exe
ProductName: Adobe Help Viewer
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Virus:Win32/Relnek.A also known as:

BkavW32.SawSailsNNA.PE
LionicVirus.Win32.Agent.n!c
MicroWorld-eScanWin32.Relnek.A
FireEyeGeneric.mg.3477144afd1441a6
CAT-QuickHealW32.Agent.CX
McAfeeW32/Relnek
CylanceUnsafe
ZillyaVirus.Agent.Win32.33
SangforVirus.Win32.Agent.cx
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Relnek.74e0376f
K7GWVirus ( 001219a61 )
K7AntiVirusVirus ( 001219a61 )
BaiduWin32.Virus.Relnek.a
VirITWin32.Relnek.A
CyrenW32/Relnek.A.gen!Eldorado
SymantecW32.Relnek.A
ESET-NOD32Win32/Agent.NAW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyVirus.Win32.Agent.cx
BitDefenderWin32.Relnek.A
NANO-AntivirusVirus.Win32.Agent.kfrya
AvastWin32:Mirecek [Inf]
TencentVirus.Win32.Agent.gee
SophosW32/Relnek-A
ComodoVirus.Win32.Relnek.A0@1n9lrd
DrWebWin32.Relnek.1
VIPREVirus.Win32.Relnek.a (v)
TrendMicroPE_RELNEK.A
McAfee-GW-EditionBehavesLike.Win32.Virut.th
EmsisoftWin32.Relnek.A (B)
JiangminWin32/Agent.o
AviraW32/Relnek.A
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASVirus.74
GridinsoftRansom.Win32.Zbot.sa
MicrosoftVirus:Win32/Relnek.A
ViRobotWin32.Relnek.A
GDataWin32.Relnek.A
AhnLab-V3Win32/Relnek.X892
BitDefenderThetaAI:FileInfector.662564C20E
ALYacWin32.Relnek.A
VBA32BScope.TrojanSpy.Zbot
TrendMicro-HouseCallPE_RELNEK.A
RisingVirus.Relnek!1.9B0F (CLASSIC)
YandexWin32.Relnek.A
MaxSecureVirus.W32.Agent.CX
FortinetW32/Relnek.A
AVGWin32:Mirecek [Inf]
Cybereasonmalicious.afd144
PandaW32/Relnek.A

How to remove Virus:Win32/Relnek.A?

Virus:Win32/Relnek.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment