Trojan Rovnix.r (1500) explorer.exe

larry d

New member
Local time
8:15 AM
Messages
26
Location
Los Gatos,Ca
Just put a new copy of w7 pro on sisters laptop by phone. Just one quick question. Will a format of the drive get rid of it completely? Nod32 says its in the operating memory. Nothing is loaded on the computer so a format would not be a problem. Thanks for any advice. p.s. I told her to wait to go online because I had not finished installing Nod32. She didn't listen obviously!
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer

My Computer My Computer

At a glance

Windows 7 Professional 32-bit/Windows 8 64-bi...Intel Core 2 Quad Q6600/Intel Core i7 4790/In...2GB/16GB/4GBIntel G33/G31 Express(Vostro)/NVIDIA GeForce ...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD
Just put a new copy of w7 pro on sisters laptop by phone. Just one quick question. Will a format of the drive get rid of it completely? Nod32 says its in the operating memory. Nothing is loaded on the computer so a format would not be a problem. Thanks for any advice. p.s. I told her to wait to go online because I had not finished installing Nod32. She didn't listen obviously!

Malwarebytes is a good suggestion by computer0304.

I'll defer to the security experts when they arrive but if it was me, I would format and reinstall.

You may want to keep her away from it till you finish the install and load the security programs this time.
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Hello and thanks for the help. Here is what I have done so far. I downloaded superantispyware and ran it. it missed the Trojan. I then sent her a copy of spyware hunter 4 paid copy. updated and ran it. It caught it an cleaned. On reboot it was back and nod32 caught it and cleaned it. But it still remained. It is in the operating memory. So rather then do a reg hack I thought a clean install would be best at this point . just want to make sure the clean install is all I need to do to get rid of it.
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer
It should be all you need, I would use the diskpart clean command,

During installation, once the Languages screen opens, do this:

1. Press SHIFT+F10 - a cmd window will open
2. Type diskpart and hit enter
3. Type list disk and hit enter
4. Type select disk # and hit enter - # = the disk number you wish to clean/format
5. Type clean and hit enter

Once complete (its quick) close the Window and continue with installation.

Just out of curiosity what are you using for install media?
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Hello and thanks for the help. Here is what I have done so far. I downloaded superantispyware and ran it. it missed the Trojan. I then sent her a copy of spyware hunter 4 paid copy. updated and ran it. It caught it an cleaned. On reboot it was back and nod32 caught it and cleaned it. But it still remained. It is in the operating memory. So rather then do a reg hack I thought a clean install would be best at this point . just want to make sure the clean install is all I need to do to get rid of it.

Did you try Malwarebytes yet?
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit/Windows 8 64-bi...Intel Core 2 Quad Q6600/Intel Core i7 4790/In...2GB/16GB/4GBIntel G33/G31 Express(Vostro)/NVIDIA GeForce ...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD
I'm using a cd I picked up for 68.00 w7 pro. I have not tried malwarebytes yet. My sister is at the wheel and she is not so savvy with computers. But I do like the diskpart Idea. Thanks everyone for the help. This is the best forum ever!! Your all super people! I will let you know how it goes.
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer
Malwarebytes found it but after reboot it came right back. I'm going to go with derekimo's suggestion . Thanks to all of you! Larry D
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer
Yeah, that's what I would do, specially since it's a recent install anyway.

I was asking about the install media in case you may have got a sketchy downloaded one but you should be good with the disc and the diskpart clean to wipe the drive.

You mention doing this over the phone, was the first install an upgrade or clean install?
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
The os came with the coa so it has to be liget right? Im on the phone with her now and she is having trouble getting it to boot from the rom. I walked her thru the bios to have it boot from the rom, but I do not know why it's not. Because I'm remote I cant access the bios. I just hope she didn't doo something wrong! Damn!! Im thinking about trying to remove it thru the reg? Is it possible?
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer
Yeah, it should be OK if you got it from a legitimate source, the COA is a good sign.

Yeah, it can be tough trying to do these things remotely.

If you want to wait for further advice from a security expert, that certainly is an option, although the remote thing may be a bit of a hindrance there too.
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Doing this remotely will be next to impossible, especially with a unsavvy user.

As annoying as it is, it might be best to have them ship you the computer, or maybe you can find a nice legit small buisness computer shop that will not rob her blind and get them to wipe the disk and install windows. Once that is done, you could use teamviewer to reset them up and make sure all security software is applied as well as all the updates.
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Andrew, I think your right about that. One hour just to set it to boot from the rom! I was pulling my hair out!! she finally got it and after reboot it still went past the cd-rom drive and booted in to windows. I will never do this again! I told her to just ship it to me or take it to a shop. It is extremely hard when you can't see what buttons the other person is pushing. I'm lucky she didn't blow up the bios!! LOL.
Lesson learned. Thanks again for the help everyone.
 

My Computer My Computer

At a glance

W7 home premium 323 bitquad [email protected] ghzfrom dell 4g@800mhzati radeon hd2600 xt pci-e 256mb
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell xps420
OS
W7 home premium 323 bit
CPU
quad [email protected] ghz
Motherboard
otp406
Memory
from dell 4g@800mhz
Graphics Card(s)
ati radeon hd2600 xt pci-e 256mb
Sound Card
pci express xtream audio
Monitor(s) Displays
dell 2707 wfp
Screen Resolution
1900 x 1200
Hard Drives
120 g/Samsung 840 ssd
PSU
375 w
Case
stock
Cooling
stock
Keyboard
dell bt
Mouse
dell bt
Internet Speed
1
Antivirus
Nod32
Browser
explorer
Other Info
logitech z5500 5.1/ Canon mp600 printer
Andrew, I think your right about that. One hour just to set it to boot from the rom! I was pulling my hair out!! she finally got it and after reboot it still went past the cd-rom drive and booted in to windows. I will never do this again! I told her to just ship it to me or take it to a shop. It is extremely hard when you can't see what buttons the other person is pushing. I'm lucky she didn't blow up the bios!! LOL.
Lesson learned. Thanks again for the help everyone.

No problem, glad you got things squared away.

My suggestions so this (hopefully) does not happen again: (email this to them)

I advise you to install and use the following security programs so you do not get infected again:

-Panda antivirus -You can only have 1 antivirus installed at a time, I recommend using this one and uninstalling what you are using now.

-Malwarebytes
-Superantispyware
-Should I remove it

Run them around once every 2 weeks.

Should I remove it is not a malware scanner. What it does is it looks at all of the installed programs on your PC and gives you a percentage % of how many people uninstall the software. If the percentage % is high, I would remove it as it is most likely not a good program. It also gives a ton of information about what the program does and how it behaves.

I also suggest using a standard user account in windows, and only using an admin account when you need to install software:

http://www.sevenforums.com/tutorials/181024-user-account-create.html

When using a standard account and you make a change or install a program that affects the whole system, UAC will prompt you to continue. Make sure the setting or program you are tying to install is listed, then click yes to continue. If you are just browsing the web and the prompt appears with a program you have not heard of, or do not know what it is, it is much safer to click no then yes. No will block the action, and if you were trying to do something, you can always start it again and choose yes.

UAC makes this easy, see here:

What is user account control (UAC)?

I also suggest choosing always notify for UAC:

What are User Account Control settings?

I also recommend that you use bleeping computers suggestions which can be found here:

So how Did I get Infected?


Those are my recommendations to you, and I Highly suggest you follow them.
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Back
Top