1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active renos.ji malware, system severely limited

Discussion in 'Malware and Virus Removal Archive' started by L99, 2009/11/12.

  1. 2009/11/12
    L99

    L99 Inactive Thread Starter

    Joined:
    2009/11/12
    Messages:
    2
    Likes Received:
    0
    [Active] renos.ji malware, system severely limited

    I believe I downloaded a trojan a few days ago. My browser started acted weird - I'd try to go to one site and it would redirect me to another. Then Windows Defender popped up saying it had found a trojan win/32/renos.ji. But when I cllicked on remove, I got a message that Defender could not remove it and then it shut down and wouldn't start again. The browser began to work only intermittently. The next day I was able to download Microsoft Safety scanner but after sitting for awhile trying to initialize the scan, it just shut down. Then while I was trying to update windows, I got a message from my McAfee virus software that an attempt was being made to alter one of the files in documents and settings\...\temp/b.exe. I blocked it several times but the windows update was stuck on 0% so I let the change take place. Now, a few days later, Intern Explorer does not work at all so I can't try to download anything to help, the system says I don't have any printers installed so I am unable to print, it doesn't recognize USB devices when I plug them in so I am unable to copy my files off the system, virus software is totally disabled, when I boot up to the desktop I get several program error messages, and I have no system tray or start menu on the desktop so the only way I know how to shut down the system is to hit the power button. I tried system restore but it wont work even in safe mode. Virus scanning won't work even in safe mode.

    At this point I'd be happy to be able to copy all my data off the machine and just buy a new computer. Is there anything that can be done to fix this or am I *******?
     
    L99,
    #1
  2. 2009/11/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try Avira AntiVir Rescue System

    Using another working computer...
    1. Download the Avira AntiVir Rescue System: http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html
    2. Place a blank CD in your burner and double-click on the downloaded file.
    3. The program will automatically burn the CD for you.
    4. Place the burned CD into the affected computer and start the computer with the CD in the CD tray.
    5. On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
    6. Click on the Configuration button.

    - Select Scan all files
    - Select Try to repair infected files and Rename files, if they cannot be removed
    - Select Scan for dialers
    - Select Scan for joke programs (Jokes)
    - Select Scan for games
    - Select Scan for spyware (SPR)

    7. Click on Virus scanner
    8. Click on Start scanner at the bottom of the screen.

    9. Let Avira finish it's scan and then remove any threats found and then exit out of the scanner.
    10. Take the CD out of the CD/DVD tray and then restart the computer.

    If needed see this Tutorial for the Avira Rescue CD: http://forum.avira.com/wbb/index.php?page=Thread&threadID=82163
     

  3. to hide this advert.

  4. 2009/11/15
    L99

    L99 Inactive Thread Starter

    Joined:
    2009/11/12
    Messages:
    2
    Likes Received:
    0
    Thanks for the help. I followed the steps you specified but after something like an hour and a half of scanning, it came up with nothing. Is there anything else I can do to remove this infection?
    Thanks
     
    L99,
    #3
  5. 2009/11/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm afraid, that without hooking the drive to another machine to run some scans, there is not much we can do here.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.