Need help, Trojan, *urgent*

Page 1 of 2 12 LastLast

  1. Posts : 79
    Windows 7 Ultimate x86 7600.16385
       #1

    Need help, Trojan, *urgent*


    Alright, here's the problem I'm having... I don't remember exactly what I downloaded, but something gave me this (It was detected by Microsoft Security Essentials) -
    TrojanDownloader:Win32/Renos.JS
    I said "meh, whatever" and clicked remove. It said successful, but about an hour later, the same thing was back again. I kept clicking remove, it kept saying it worked, and it kept coming back. Now Microsoft Security Essentials is saying "Microsoft Security Essentials isn't monitering your computer because the program's service is stopped. You should restart it now." Sure. So I click the big red button which says "Start" and I get this..
    Couldn't start the Microsoft Security Essentials service - Access is denied. Error code: 0x80070005

    Now, every time I boot my computer up and login to a user, explorer.exe no longer runs on startup, so I am forced to manually start it. On top of that, my default browser (Mozilla Firefox) crashes every time I open it. Did I mention my internet connection isn't reliable at the moment, and could disconnect at any time? Headache after headache.. Please, PLEASE, someone help me fix this crap. It's really getting on my nerves. Thanks..

    ~TA
      My Computer


  2. Posts : 4,573
       #2

    Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (http://safety.live.com). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.

    System Changes

    The following system changes may indicate the presence of this malware:

    • The presence of the following registry modifications (or similar):
      Value: MSFox
      With data: <full pathname of Win32/Renos<variant>>
      In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run

      Value: Str<digit>
      With data: <base64 encoded string> (for example, "x6tveq8ngbtmpknqirnnqauudxwx")
      In subkey: HKLM\Software\Mozilla\MSFox
      My Computer


  3. Posts : 9,606
    Win7 Enterprise, Win7 x86 (Ult 7600), Win7 x64 Ult 7600, TechNet RTM on AMD x64 (2.8Ghz)
       #3

    I agree with Antman, sounds like it could be malware saying you have a trojan virus.

    Try MalWareBytes running in safe mode to see if it can clean all malware on you drive.

    Link:

    http://www.malwarebytes.org/
    Last edited by DocBrown; 15 Oct 2009 at 21:48. Reason: added link
      My Computer


  4. Posts : 79
    Windows 7 Ultimate x86 7600.16385
    Thread Starter
       #4

    I'm 99.9% positive it isn't malware. I've not yet seen malware that can control the Microsoft Security Essentials GUI..
      My Computer


  5. Posts : 4,573
       #5

    Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (http://safety.live.com). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.

    System Changes

    The following system changes may indicate the presence of this malware:

    • The presence of the following registry modifications (or similar):
      Value: MSFox
      With data: <full pathname of Win32/Renos<variant>>
      In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run

      Value: Str<digit>
      With data: <base64 encoded string> (for example, "x6tveq8ngbtmpknqirnnqauudxwx")
      In subkey: HKLM\Software\Mozilla\MSFox
      My Computer


  6. Posts : 53
    Windows 7 RTM 7127
       #6

    TheAnonymity said:
    Alright, here's the problem I'm having... I don't remember exactly what I downloaded, but something gave me this (It was detected by Microsoft Security Essentials) -
    TrojanDownloader:Win32/Renos.JS
    I said "meh, whatever" and clicked remove. It said successful, but about an hour later, the same thing was back again. I kept clicking remove, it kept saying it worked, and it kept coming back. Now Microsoft Security Essentials is saying "Microsoft Security Essentials isn't monitering your computer because the program's service is stopped. You should restart it now." Sure. So I click the big red button which says "Start" and I get this..
    Couldn't start the Microsoft Security Essentials service - Access is denied. Error code: 0x80070005

    Now, every time I boot my computer up and login to a user, explorer.exe no longer runs on startup, so I am forced to manually start it. On top of that, my default browser (Mozilla Firefox) crashes every time I open it. Did I mention my internet connection isn't reliable at the moment, and could disconnect at any time? Headache after headache.. Please, PLEASE, someone help me fix this crap. It's really getting on my nerves. Thanks..

    ~TA
    Microsoft recommends either a-squared Free or mailwarebytes..

    Both Free Programs. I had the same bug and this took care of it.
      My Computer


  7. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #7

    Umm, ***OS... Windows 7 RC Build 7057

    TrojanDownloader:Win32/Renos.JS
    This is a 'fake' Anti-virus' downloader .... it's also called Vundo and may have included Rootkit along with it.

    I don't advocate cleaning up Rootkits on a computer because you can never be sure that your OS will ever be stable again. I draw the line at Rootkits.

    I personally would wipe and do a ***clean Windows installation (not the RC build version that you have now!).

    How to prevent Malware:
    http://miekiemoes.blogspot.com/2008/...t-malware.html
      My Computer


  8. Posts : 4,573
       #8

    Jacee is the resident subject matter expert on this topic. You are well-advised. There is simply no one else on this forum with more expertise in the subject.
      My Computer


  9. Posts : 3
    Windows vista
       #9

    Fisrtly apologies for my ignorance as i am new to all things pc. I also have the same issue whereby it wont remove - it seems like it has been removed but when opening internet explorer and looking in the history random sites appear that have never been visited - i already have a norton product installed on my machine and the trojan was picked up by windows defender - although still appears even after removal - what are the quickets and easiest steps for a novice like me to resolve the issue - any step by step process would be greatly appreciated
      My Computer


  10. Posts : 3
    Windows vista
       #10

    sorry in addition i did run a full system scan with the norton product but it came back with no results
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:01.
Find Us