Malware

Should I remove “W32/Renamer-K”?

Malware Removal

The W32/Renamer-K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Renamer-K virus can do?

  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Creates known Renamer mutexes

How to determine W32/Renamer-K?


File Info:

name: 590716E18BD5062B59A1.mlw
path: /opt/CAPEv2/storage/binaries/8a7bb2cb0180b8c43ec6847e314fc7f192d86bd16774718f14a7ad9e19faee8c
crc32: 41E6445B
md5: 590716e18bd5062b59a1e5e99722b577
sha1: 1e1f4749240b6c995825c480af94d6676f136144
sha256: 8a7bb2cb0180b8c43ec6847e314fc7f192d86bd16774718f14a7ad9e19faee8c
sha512: de19ea150b2c5f91f33d46a05c150d8d979dda6bbda53d8151ca63479844dd01f417573134cee497d59eaeed24e4a979c95746ea2e7a249d7f1cb1d29fb46098
ssdeep: 12288:qaMIztyCK5x8CBmn+RrNbEHWYa0Ie1vUx9Vr:bZyCA8CBmn+RrNO9ay5Ir
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3B49F71F7D09537D1371BB88C1BA2A9A8397F102E2864467BE81D4C9F397C139292E7
sha3_384: 80e0e0a9490f46e00878039e7b27df75e3992228776bede5c99b3e4f40b019ae22c5c5fef9b0cb78827510e4aabb8eb6
ep_bytes: 558bec83c4f053b8140e4700e8434af9
timestamp: 2004-05-15 17:24:46

Version Info:

0: [No Data]

W32/Renamer-K also known as:

BkavW32.FakeExeYHPtv.Worm
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.590716e18bd5062b
CAT-QuickHealW32.Grenam.A9
SkyhighBehavesLike.Win32.Gnamer.hh
McAfeeW32/Gnamer
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Malware.GKW@aSux1dhi
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000c8b551 )
K7GWTrojan ( 004d4f8e1 )
Cybereasonmalicious.9240b6
BaiduWin32.Worm.Delf.bi
VirITWorm.Win32.Delf.KHX
SymantecW32.Tapin
ESET-NOD32Win32/Delf.NRJ
APEXMalicious
ClamAVWin.Virus.Gnamer-1
KasperskyVirus.Win32.Renamer.j
BitDefenderGen:Trojan.Malware.GKW@aSux1dhi
NANO-AntivirusTrojan.Win32.Renamer.lnwkz
MicroWorld-eScanGen:Trojan.Malware.GKW@aSux1dhi
AvastWin32:Renamer-F [Trj]
TencentTrojan.Win32.Renamer.ttk
TACHYONWorm/W32.DP-Renamer.534016
EmsisoftGen:Trojan.Malware.GKW@aSux1dhi (B)
F-SecureMalware.W32/Renamer.A
DrWebWin32.HLLC.Sorrypic.1
ZillyaBackdoor.Ghoster.Win32.59
TrendMicroTrojan.Win32.GRENAM.SM
SophosW32/Renamer-K
IkarusVirus.Win32.Renamer
GDataWin32.Trojan.PSE.1CER05K
JiangminWorm/Delf.yc
WebrootW32.Malware.gen
GoogleDetected
AviraW32/Renamer.A
Antiy-AVLVirus/Win32.Renamer.j
XcitiumWorm.Win32.Delf.nj@4ri78u
ArcabitTrojan.Malware.EED5E6
ViRobotWin32.Renamer.A
ZoneAlarmVirus.Win32.Renamer.j
MicrosoftVirus:Win32/Grenam.VA!MSR
VaristW32/Delf.EA.gen!Eldorado
AhnLab-V3Trojan/Win32.Renamer.R54474
Acronissuspicious
BitDefenderThetaAI:Packer.1B57CBDF21
ALYacGen:Trojan.Malware.GKW@aSux1dhi
MAXmalware (ai score=88)
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaW32/Renamer.F.worm
ZonerTrojan.Win32.87681
TrendMicro-HouseCallTrojan.Win32.GRENAM.SM
RisingWorm.Renamer!1.DE00 (CLASSIC)
YandexTrojan.GenAsa!bFkr50Cc7zI
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Renamer.J
FortinetW32/Injector.2F48!tr
AVGWin32:Renamer-F [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Renamer-K?

W32/Renamer-K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment