Home / malwarePDF  

Rogue:W32/Renos


First posted on 19 April 2010.
Source: SecurityHome

Aliases :

There are no other names known for Rogue:W32/Renos.

Explanation :

Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected.

Additional DetailsRogue:W32/Renos is program that displays annoying fake security warnings. The aim of this software is to trick a computer user to download third-party cleaning utilities, usually anti-spyware scanners.

Installation

The Renos executable file is usually dropped by malicious websites onto the computer system. It may also be delivered in the payload of a trojan.

Typically when a Renos' executable file is run, it drops a DLL file into Windows System folder and registers it as a system component. The DLL is the main Renos component.

Activity

When active, Renos shows a blinking icon in System Tray and periodically (actually quite often to be annoying) shows a fake security warning:



When a user clicks on this alert, his web browser is redirected to a website that offers a cleaning utility (usually anti-adware) for download.

Last update 19 April 2010

 

TOP