Go Back   TechArena Community > Technical Support > Computer Help > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Renos.y trojan in XP Professional

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 16-10-2008
Gary Adams Lsu Edu
 
Posts: n/a
Renos.y trojan in XP Professional

Virus or trojan in my Windows XP desktop.

Live care found ; renos.y

This XP Professional Compaq Evo has a trojan or virus.

It was cleaned with;

1. Ad Aware
2. Spy Bot Search and Destroy
3. Microsoft Live One Care

Somewhere in the registry there is a startup or run command that created an
excutable file in the c:\Windows\Temp directory. But I cannot find it.
i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg
Here is the registry info relating to the new file found in the Temp folder
after each restart.
The filename changes at each restaRT.

PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe

Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations

Session Manager
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe

ControlSet003
BackupRestore
KeysNotToRestore
Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations

ControlSet same as above

SessionMangeger
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe

It is somwhere in the autostart area of the registry ?

Reply With Quote
  #2  
Old 16-10-2008
Malke
 
Posts: n/a
Re: Renos.y trojan in XP Professional

Gary Adams Lsu Edu wrote:

> Virus or trojan in my Windows XP desktop.
>
> Live care found ; renos.y
>
> This XP Professional Compaq Evo has a trojan or virus.
>
> It was cleaned with;
>
> 1. *Ad Aware
> 2. *Spy Bot Search and Destroy
> 3. *Microsoft Live One Care
>
> Somewhere in the registry there is a startup or run command that created
> an excutable file in the c:\Windows\Temp directory. *But I cannot find it.
> i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg
> Here is the registry info relating to the new file found in the Temp
> folder after each restart.
> The filename changes at each restaRT.
>
> PendingFileRenameOperations
> \??\C:\WINDOWS\TEMP\E1167036.exe
>
> Pending Rename Operations
> CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
>
> Session Manager
> PendingFileRenameOperations
> \??\C:\WINDOWS\TEMP\E1167036.exe


(snippage)

It probably has a guard file. Since I don't know how you cleaned (eg., did
you do prep work? scan in Safe Mode?), follow the general malware removal
steps at this link:

http://www.elephantboycomputers.com/...moving_Malware

Include scanning with David Lipman's Multi_AV and follow instructions to do
all scans in Safe Mode. Please see the special Notes regarding using
Multi_AV in Vista.

http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions
http://tinyurl.com/yoeru3 - download link and more instructions

When all else fails, get guided help. Choose one of the specialty forums
listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
POST LOGS IN THE MS NEWSGROUPS.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

Reply With Quote
  #3  
Old 18-10-2008
Dell Techie
 
Posts: n/a
RE: Renos.y trojan in XP Professional

Turn off and turn your system restore back on to flush the virus from the
restore folder.

Run a clean up tool to remove the other virus from other temp folders
http://securitynewsfromthenet.blogsp...ople-from.html


Run Malwarebytes Anti-Malware
http://securitynewsfromthenet.blogsp...lware-105.html

Run an online scan
http://spywarefighter.blogspot.com/2...line-scan.html
http://spywarefighter.blogspot.com/2...irus-scan.html
Reply With Quote
  #4  
Old 06-01-2009
ares
 
Posts: n/a
RE: Renos.y trojan in XP Professional

DELL techie, I hope that's just your handle not your job. It comes close to
being rule one for malware removal...as well as downloading in
general..ALWAYS go to the source, even if innocently intended..spyware
fighter to trend micro gives more garbage double the chance to get in.
Physician heal thy self,
Darrel

"Dell Techie" wrote:

> Turn off and turn your system restore back on to flush the virus from the
> restore folder.
>
> Run a clean up tool to remove the other virus from other temp folders
> http://securitynewsfromthenet.blogsp...ople-from.html
>
>
> Run Malwarebytes Anti-Malware
> http://securitynewsfromthenet.blogsp...lware-105.html
>
> Run an online scan
> http://spywarefighter.blogspot.com/2...line-scan.html
> http://spywarefighter.blogspot.com/2...irus-scan.html

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Renos.y trojan in XP Professional"
Thread Thread Starter Forum Replies Last Post
What is TR/Dldr.Renos.PG.56? GaganjyotTechie Networking & Security 4 12-06-2011 12:01 PM
Trojan downloader:JS/Renos and Why doesn't microsoft detect my activation jnp5053 Windows Security 5 23-06-2009 01:15 AM
Win32/renos.io Scot Vista Help 2 10-06-2009 07:17 AM
TrojanDownloader:Win32/Renos.DU Mhaxx Windows Security 6 23-01-2009 03:43 AM
Mobiado announced Professional 105 EM White, Professional 105 EM Red, Professional 105 EM CLB Black and Professional 105 EM CLB Silver. JamesMK Portable Devices 0 21-10-2008 02:31 PM


All times are GMT +5.5. The time now is 05:42 PM.