Trojan.Renos.PGZ
Unusual processes might appear such as: kgl.exe, kgj.exe, kgk.exe
Presence of the following files and registry entry modifications:
Please let BitDefender disinfect your files.
Trojan.Renos.PGZ is a trojan downloader which connects to certain websites in order to download and execute malicious files.
Modifies Internet Explorer settings (to lower security settings) by modifying the following registry entries:
It creates and executes the file: %TEMP%\[3-random-letters]..bat, which tries to delete the downloader until succeeds, after which deletes itself.
Downloads from:
three files to %TEMP%\[3-random-letters].exe (ex. kgl.exe, kgj.exe, kgk.exe) and executes them.
The downloaded files are detected by BitDefender as Trojan.Renos.PHH.
Some of them will download additional files from sites such as:
One of the downloaded files is a keylogger which sends the list of keystrokes to http://cyber[removed].com
A symptom of infection is the presence of new scheduled tasks in C:\Windows\Tasks directory and
of a random key under the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ registry key. These are added to ensure that the malware will run at system startup.
SHARE
THIS ON