|
| |||||||||
| Tags: professional, renosy |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Renos.y trojan in XP Professional
Virus or trojan in my Windows XP desktop. Live care found ; renos.y This XP Professional Compaq Evo has a trojan or virus. It was cleaned with; 1. Ad Aware 2. Spy Bot Search and Destroy 3. Microsoft Live One Care Somewhere in the registry there is a startup or run command that created an excutable file in the c:\Windows\Temp directory. But I cannot find it. i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg Here is the registry info relating to the new file found in the Temp folder after each restart. The filename changes at each restaRT. PendingFileRenameOperations \??\C:\WINDOWS\TEMP\E1167036.exe Pending Rename Operations CurrentControlSet\Control\Session Manager\PendingFileRenameOperations Session Manager PendingFileRenameOperations \??\C:\WINDOWS\TEMP\E1167036.exe ControlSet003 BackupRestore KeysNotToRestore Pending Rename Operations CurrentControlSet\Control\Session Manager\PendingFileRenameOperations ControlSet same as above SessionMangeger PendingFileRenameOperations \??\C:\WINDOWS\TEMP\E1167036.exe It is somwhere in the autostart area of the registry ? |
|
#2
| |||
| |||
| Re: Renos.y trojan in XP Professional
Gary Adams Lsu Edu wrote: > Virus or trojan in my Windows XP desktop. > > Live care found ; renos.y > > This XP Professional Compaq Evo has a trojan or virus. > > It was cleaned with; > > 1. *Ad Aware > 2. *Spy Bot Search and Destroy > 3. *Microsoft Live One Care > > Somewhere in the registry there is a startup or run command that created > an excutable file in the c:\Windows\Temp directory. *But I cannot find it. > i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg > Here is the registry info relating to the new file found in the Temp > folder after each restart. > The filename changes at each restaRT. > > PendingFileRenameOperations > \??\C:\WINDOWS\TEMP\E1167036.exe > > Pending Rename Operations > CurrentControlSet\Control\Session Manager\PendingFileRenameOperations > > Session Manager > PendingFileRenameOperations > \??\C:\WINDOWS\TEMP\E1167036.exe (snippage) It probably has a guard file. Since I don't know how you cleaned (eg., did you do prep work? scan in Safe Mode?), follow the general malware removal steps at this link: http://www.elephantboycomputers.com/...moving_Malware Include scanning with David Lipman's Multi_AV and follow instructions to do all scans in Safe Mode. Please see the special Notes regarding using Multi_AV in Vista. http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions http://tinyurl.com/yoeru3 - download link and more instructions When all else fails, get guided help. Choose one of the specialty forums listed at the first link. Register and read its posting FAQ. PLEASE DO NOT POST LOGS IN THE MS NEWSGROUPS. Malke -- MS-MVP Elephant Boy Computers - Don't Panic! FAQ - http://www.elephantboycomputers.com/#FAQ |
|
#3
| |||
| |||
| RE: Renos.y trojan in XP Professional
Turn off and turn your system restore back on to flush the virus from the restore folder. Run a clean up tool to remove the other virus from other temp folders http://securitynewsfromthenet.blogsp...ople-from.html Run Malwarebytes Anti-Malware http://securitynewsfromthenet.blogsp...lware-105.html Run an online scan http://spywarefighter.blogspot.com/2...line-scan.html http://spywarefighter.blogspot.com/2...irus-scan.html |
|
#4
| |||
| |||
| RE: Renos.y trojan in XP Professional
DELL techie, I hope that's just your handle not your job. It comes close to being rule one for malware removal...as well as downloading in general..ALWAYS go to the source, even if innocently intended..spyware fighter to trend micro gives more garbage double the chance to get in. Physician heal thy self, Darrel "Dell Techie" wrote: > Turn off and turn your system restore back on to flush the virus from the > restore folder. > > Run a clean up tool to remove the other virus from other temp folders > http://securitynewsfromthenet.blogsp...ople-from.html > > > Run Malwarebytes Anti-Malware > http://securitynewsfromthenet.blogsp...lware-105.html > > Run an online scan > http://spywarefighter.blogspot.com/2...line-scan.html > http://spywarefighter.blogspot.com/2...irus-scan.html |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Renos.y trojan in XP Professional" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| What is TR/Dldr.Renos.PG.56? | GaganjyotTechie | Networking & Security | 4 | 12-06-2011 12:01 PM |
| Trojan downloader:JS/Renos and Why doesn't microsoft detect my activation | jnp5053 | Windows Security | 5 | 23-06-2009 01:15 AM |
| Win32/renos.io | Scot | Vista Help | 2 | 10-06-2009 07:17 AM |
| TrojanDownloader:Win32/Renos.DU | Mhaxx | Windows Security | 6 | 23-01-2009 03:43 AM |
| Mobiado announced Professional 105 EM White, Professional 105 EM Red, Professional 105 EM CLB Black and Professional 105 EM CLB Silver. | JamesMK | Portable Devices | 0 | 21-10-2008 02:31 PM |