Need help, Trojan, *urgent*

TheAnonymity

New member
Local time
6:35 AM
Messages
79
Alright, here's the problem I'm having... I don't remember exactly what I downloaded, but something gave me this (It was detected by Microsoft Security Essentials) -
TrojanDownloader:Win32/Renos.JS
I said "meh, whatever" and clicked remove. It said successful, but about an hour later, the same thing was back again. I kept clicking remove, it kept saying it worked, and it kept coming back. Now Microsoft Security Essentials is saying "Microsoft Security Essentials isn't monitering your computer because the program's service is stopped. You should restart it now." Sure. So I click the big red button which says "Start" and I get this..
Couldn't start the Microsoft Security Essentials service - Access is denied. Error code: 0x80070005

Now, every time I boot my computer up and login to a user, explorer.exe no longer runs on startup, so I am forced to manually start it. On top of that, my default browser (Mozilla Firefox) crashes every time I open it. Did I mention my internet connection isn't reliable at the moment, and could disconnect at any time? Headache after headache.. Please, PLEASE, someone help me fix this crap. It's really getting on my nerves. Thanks..

~TA
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1501
OS
Windows 7 Ultimate x86 7600.16385
CPU
AMD Turion 64 Mobile Technology MK-36 2.00 GHz
Motherboard
Dell UW953
Memory
1.00 GB (894 MB usable)
Graphics Card(s)
ATI Radeon XPRESS 128MB
Sound Card
Dunno
Monitor(s) Displays
15"
Screen Resolution
1280 x 800
Hard Drives
Fujitsu MJA2080BH G2 ATA Device (80 GB, 5400 RPM)
Cooling
Laptop fans ftw.
Keyboard
Laptop Keyboard..
Mouse
Laptop touchpad..
Internet Speed
16.45 Mb/s download, 3.84 Mb/s upload
Other Info
My computer sucks.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (http://safety.live.com). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.

System Changes

The following system changes may indicate the presence of this malware:

  • The presence of the following registry modifications (or similar):
    Value: MSFox
    With data: <full pathname of Win32/Renos<variant>>
    In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Value: Str<digit>
    With data: <base64 encoded string> (for example, "x6tveq8ngbtmpknqirnnqauudxwx")
    In subkey: HKLM\Software\Mozilla\MSFox​
 
I agree with Antman, sounds like it could be malware saying you have a trojan virus.

Try MalWareBytes running in safe mode to see if it can clean all malware on you drive.

Link:

http://www.malwarebytes.org/
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built them myself, Science Experiments !
OS
Win7 Enterprise, Win7 x86 (Ult 7600), Win7 x64 Ult 7600, TechNet RTM on AMD x64 (2.8Ghz)
CPU
AMD fx8350 4ghz, AMD-32 2400mhz, AMD-64 3200mhz, AMDx64 2.8G
Motherboard
SIS 755, ECS-K8M890M-M (Ult 7600), GigaByte & others
Memory
2gb, 4gb on the Ult 7600, 4gb on Technet RTM, 32gb on FX8350
Graphics Card(s)
Draw my own Graphics, several nVidia cards
Sound Card
on motherboard
Monitor(s) Displays
19" flat scr, 28" I-Inc widescr,22" Emprex Widescr, 23" Acer
Screen Resolution
1280 x 1024, 1440 x 900, 1920 x 1080
Hard Drives
6 pata Ide HD's & 2 Sata HD's
added 80gb external on Ult 7600 computer,
numerous extra 1tb, 2TB, 3Tb SATA HD's
A collection of ext HD Docks w/ HDs
PSU
430w, 550w, 600w, 700, 800, etc
Case
All Generic Full Towers
Cooling
Open Air & a few fans, some w/ colored LEDs
Keyboard
Compaq & Dell recycled from GoodWill
Mouse
Made in China Optical Wired Mouse
Internet Speed
Fast Cable InterNet
Antivirus
AVG Free on 24 different Desktops, NO Problems!
Browser
IE 8 is preferred, but use FireFox sometimes
Other Info
Linksys Routers, switches, & Hubs
Too Many USB Flash Drives to count, Biggest is 64GB !
Eight computers in my home network.
Sixteen computers at my business network.
Linked via TeamViewer !
Lots of old used spare computer parts everywhere!
I'm 99.9% positive it isn't malware. I've not yet seen malware that can control the Microsoft Security Essentials GUI..
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1501
OS
Windows 7 Ultimate x86 7600.16385
CPU
AMD Turion 64 Mobile Technology MK-36 2.00 GHz
Motherboard
Dell UW953
Memory
1.00 GB (894 MB usable)
Graphics Card(s)
ATI Radeon XPRESS 128MB
Sound Card
Dunno
Monitor(s) Displays
15"
Screen Resolution
1280 x 800
Hard Drives
Fujitsu MJA2080BH G2 ATA Device (80 GB, 5400 RPM)
Cooling
Laptop fans ftw.
Keyboard
Laptop Keyboard..
Mouse
Laptop touchpad..
Internet Speed
16.45 Mb/s download, 3.84 Mb/s upload
Other Info
My computer sucks.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (http://safety.live.com). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.

System Changes

The following system changes may indicate the presence of this malware:​

  • The presence of the following registry modifications (or similar):
    Value: MSFox
    With data: <full pathname of Win32/Renos<variant>>
    In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run​

    Value: Str<digit>
    With data: <base64 encoded string> (for example, "x6tveq8ngbtmpknqirnnqauudxwx")
    In subkey: HKLM\Software\Mozilla\MSFox​
 
Alright, here's the problem I'm having... I don't remember exactly what I downloaded, but something gave me this (It was detected by Microsoft Security Essentials) -
TrojanDownloader:Win32/Renos.JS
I said "meh, whatever" and clicked remove. It said successful, but about an hour later, the same thing was back again. I kept clicking remove, it kept saying it worked, and it kept coming back. Now Microsoft Security Essentials is saying "Microsoft Security Essentials isn't monitering your computer because the program's service is stopped. You should restart it now." Sure. So I click the big red button which says "Start" and I get this..
Couldn't start the Microsoft Security Essentials service - Access is denied. Error code: 0x80070005

Now, every time I boot my computer up and login to a user, explorer.exe no longer runs on startup, so I am forced to manually start it. On top of that, my default browser (Mozilla Firefox) crashes every time I open it. Did I mention my internet connection isn't reliable at the moment, and could disconnect at any time? Headache after headache.. Please, PLEASE, someone help me fix this crap. It's really getting on my nerves. Thanks..

~TA

Microsoft recommends either a-squared Free or mailwarebytes..

Both Free Programs. I had the same bug and this took care of it.
 

My Computer

OS
Windows 7 RTM 7127
Umm, ***OS... Windows 7 RC Build 7057

TrojanDownloader:Win32/Renos.JS
This is a 'fake' Anti-virus' downloader .... it's also called Vundo and may have included Rootkit along with it.

I don't advocate cleaning up Rootkits on a computer because you can never be sure that your OS will ever be stable again. I draw the line at Rootkits. :mad:

I personally would wipe and do a ***clean Windows installation (not the RC build version that you have now!).

How to prevent Malware:
http://miekiemoes.blogspot.com/2008/02/how-to-prevent-malware.html
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Jacee is the resident subject matter expert on this topic. You are well-advised. There is simply no one else on this forum with more expertise in the subject.
 
Fisrtly apologies for my ignorance as i am new to all things pc. I also have the same issue whereby it wont remove - it seems like it has been removed but when opening internet explorer and looking in the history random sites appear that have never been visited - i already have a norton product installed on my machine and the trojan was picked up by windows defender - although still appears even after removal - what are the quickets and easiest steps for a novice like me to resolve the issue - any step by step process would be greatly appreciated
 

My Computer

Computer Manufacturer/Model Number
Toshiba
OS
Windows vista
sorry in addition i did run a full system scan with the norton product but it came back with no results
 

My Computer

Computer Manufacturer/Model Number
Toshiba
OS
Windows vista
Read 3 posts up...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
thanks - again apologies for my lack of experience i will follow Jacee's advise - is it possiible to advise step by step how i do this - as i say i am very inexperienced on pc's
 

My Computer

Computer Manufacturer/Model Number
Toshiba
OS
Windows vista
As stated before, its just a better way to wipe out your HD and do a clean installation so you can be for sure safe
 

My Computer

Computer Manufacturer/Model Number
HP a6720f
OS
7 Ultimate x64 RTM 7600.16385
CPU
AMD Phenom 9550 @ 2.20ghz
Motherboard
Asus M2N78-LA
Memory
4x2GB DDR2 Patriot Viper 800mhz
Graphics Card(s)
GeForce 9400 GT 512MB
Sound Card
Onboard Realtek Hi-Definition ALC 888S chipset
Monitor(s) Displays
Samsung P2370HD 23" 1080P HDTV
Screen Resolution
1920x1080
Hard Drives
Western Digital 640GB; Samsung 1 TB; WD 500GB; Seagate Portable 250gb;
Keyboard
Logitech LX310 Wireless Internet Keyboard
Mouse
Logitech LX310 Wireless Laser Mouse
Internet Speed
7Mbps/384Kbps
thanks - again apologies for my lack of experience i will follow Jacee's advise - is it possiible to advise step by step how i do this - as i say i am very inexperienced on pc's
Insert installation medium. Boot. Install.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top