Computing.Net > Forums > Security and Virus > Can't remove Win32/Renos.dz please help :(

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can't remove Win32/Renos.dz please help :(

Reply to Message Icon

Name: Zerzeus
Date: June 26, 2009 at 01:01:06 Pacific
OS: Windows XP
CPU/Ram: 1.18gb
Subcategory: Viruses
Comment:

I've recently got infected with a virus called TrojanDownloader:Win32/Renos.dz.Window alerted me about it and i attempted to remove it with Window defender and thought that the treat was gone.But it seems to come back again everytime i remove it.about every 30 minutes it happened.

i tried to go on safe mode and run all my anti-virus
SpyBot S&D
MalwareBytes Anti-Malware
Window Defender

but both Malware Bytes and SpyBot wasn't able to detect that virus.
Window Defender also didn't detect that virus until later when that same warning pop up.

Hope you can help me out of this one :(



Sponsored Link
Ads by Google

Response Number 1
Name: jdk (by neoark)
Date: June 26, 2009 at 07:11:45 Pacific
Reply:

Download and run Kaspersky AVP tool: http://devbuilds.kaspersky-labs.com...
Once you download and start the tool:

# Check below options:

    * Select all the objects/places to be scanned. 
    * Settings > Customize > Heuristic analyzer > Enable deep rootkit search

# Click Scan
# Fix what it detects
# Attach Scan log/Summary to your next message.

Illustrated tutorial: http://img32.imageshack.us/img32/76...

If I'm helping you and I don't reply within 24 hours send me a PM.


0

Response Number 2
Name: Zerzeus
Date: June 26, 2009 at 14:49:13 Pacific
Reply:

sorry the scan is now currently at 5% after 5hours..but don't worry i'll send the log to you as soon as it is done.

i appreciate the help and sorry for late reply


0

Response Number 3
Name: jdk (by neoark)
Date: June 26, 2009 at 14:53:21 Pacific
Reply:

To speed it up a bit close all running spyware/antivirus protection. Run the scan in safe mode.

If I'm helping you and I don't reply within 24 hours send me a PM.


0

Response Number 4
Name: Zerzeus
Date: June 27, 2009 at 04:42:47 Pacific
Reply:

Scan
----
Scanned: 3518550
Detected: 14
Untreated: 0
Start time: 6/26/2009 9:44:53 AM
Duration: 18:36:10
Finish time: 6/27/2009 4:21:03 AM


Detected
--------
Status Object
------ ------
will be deleted when the computer is restarted: Trojan program Trojan.Win32.FraudPack.own File: c:\windows\msa.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyl File: C:\Documents and Settings\Zodax\Desktop\Pareto_AV_Setup_RW.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyp File: C:\Documents and Settings\Zodax\Local Settings\Application Data\Downloaded Installations\{1B4C9447-81FA-43E8-89FE-9CA0D9B4EB39}\ParetoLogic Anti-Virus PLUS.msi//Data1.cab/paretoshellext.dll
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: C:\Documents and Settings\Zodax\Local Settings\Application Data\Downloaded Installations\{1B4C9447-81FA-43E8-89FE-9CA0D9B4EB39}\ParetoLogic Anti-Virus PLUS.msi//Data1.cab/pareto_av.exe
deleted: Trojan program Trojan.Win32.FraudPack.own File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP11\A0002273.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyl File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP11\A0002276.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyp File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP11\A0002277.msi//Data1.cab/paretoshellext.dll
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP11\A0002277.msi//Data1.cab/pareto_av.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyp File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP7\A0002174.msi//Data1.cab/paretoshellext.dll
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP7\A0002174.msi//Data1.cab/pareto_av.exe
deleted: Trojan program Trojan.Win32.FraudPack.oyp File: D:\System Volume Information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP9\A0002199.RBF
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: D:\System Volume Information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP9\A0002200.RBF
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP11\A0002277.msi//Data1.cab
deleted: Trojan program Trojan.Win32.FraudPack.oyq File: C:\system volume information\_restore{1A2FE54D-9D26-4B44-ADCA-479EBEE5A642}\RP7\A0002174.msi//Data1.cab


Events
------
Time Name Status Reason
---- ---- ------ ------
6/26/2009 9:45:04 AM Running module: smss.exe\smss.exe ok scanned


Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------


Settings
--------
Parameter Value
--------- -----
Security Level Custom
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search Yes
Use heuristic analyzer Yes


Quarantine
----------
Status Object Size Added
------ ------ ---- -----


Backup
------
Status Object Size
------ ------ ----


Sorry it took so long :D
thanks again


0

Response Number 5
Name: jdk (by neoark)
Date: June 27, 2009 at 06:47:14 Pacific

Related Posts

See More



Response Number 6
Name: Zerzeus
Date: June 27, 2009 at 08:23:34 Pacific
Reply:

so far so good thanks for your help :D

i'll confirm with you again next weekend,i got school.

but i think it's gone for good because window defender will tell me it found the Win32/Renos. dz every time i switch on my computer.Thanks for taking your time to help me :D


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can't remove Win32/Renos.dz please help :(

viruses found but can't remove them www.computing.net/answers/security/viruses-found-but-cant-remove-them/2495.html

Norton can't remove it www.computing.net/answers/security/norton-cant-remove-it/23319.html

Win32/Renos.dz -- can't get rid of it! www.computing.net/answers/security/win32renosdz-cant-get-rid-of-it/26277.html