Home / malwarePDF  

TrojanDownloader:Win32/Renos.IR


First posted on 06 July 2009.
Source: SecurityHome

Aliases :

TrojanDownloader:Win32/Renos.IR is also known as Also Known As:Win32/FakeAV.AVQ (CA), :Adware/SystemSecurity (Panda), Trojan.Fakeavalert (Symantec).

Explanation :

TrojanDownloader:Win32/Renos.IR is a detection for a member of the TrojanDownloader:Win32/Renos family. It downloads and executes other malware from, and reports infections to, a remote server.

Symptoms
There are no common symptoms associated with this threat. Alert notifications from installed antivirus software may be the only symptom(s).

TrojanDownloader:Win32/Renos.IR is a detection for a member of the TrojanDownloader:Win32/Renos family. It downloads and executes other malware from, and reports infections to, a remote server. It is known to download a file as '%Temp%inne.tmp', detected as Trojan:Win32/Winwebsec, from the remote server 'you-adult-tube.co.cc'. It also attempts to report infection of a system to that server.

Analysis by Shawn Wang

Last update 06 July 2009

 

TOP