Home Malware Programs Trojans Trojan.Renos

Trojan.Renos

Posted: August 28, 2009

Trojan.Renos (also referred to as Trojan.Renos.G and Trojan.Renos.M) is a Trojan horse capable of infiltrating your computer without your knowledge or consent, and begin downloading additional malware onto the PC in order to compromise it further. Trojan.Renos may also allow a hacker to take complete control of your system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iebtm.exe
    2 lsass.exe
    3 navf.dll
    4 phtrc345015.exe
    5 pphcc4dj0epbv.exe
    6 pphcj7cj0ea59.exe
    7 pphcpgsj0ega1.exe
    8 sprof.exe
    9 vvihh.dll
    10 wcs.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{1AB6932F-92FE-42E6-870C-544AE458EA78}HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Lsass ServiceHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{b36d60c8-e1ce-464e-b74c-8128a627ef56}RUNNING PROGRAMiebtm.exeRUNNING PROGRAMpphcc4dj0epbv.exeRUNNING PROGRAMpphcj7cj0ea59.exeRUNNING PROGRAMpphcpgsj0ega1.exeRUNNING PROGRAMwcs.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ realtecssHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sprof
Loading...