Jump to content

Reno Trojan


decaff

Recommended Posts

I recently got somehow infected with a trojan that simply kept popping up on my Windows security for deletion, repeatedly. So I ran an AVG free full system scan which turned up nothing. Concerned I searched the internet for help and came across Malwarebytes and decided to use it, however upon clicking "Quick Scan" just after installation it froze for a second and then closed, whenever I subsequently attempt to use Malwarebytes I get the message "Windows cannot access the specified..." you know how it goes.

So upon browsing these forums I saw the instructions for running combofix, so I did. Afterwards however I found I could not run anything at all outside of safe mode, getting a registry key modification warning bubble. I do however have the combofix log:

ComboFix 09-09-29.02 - Andy 30/09/2009 10:06.1.4 - NTFSx86

Microsoft

Link to post
Share on other sites

Small update, managed to get Mbam working by installing it again and running it in safe mode, a quick scan found one file which I chose to delete. Here's the log:

Malwarebytes' Anti-Malware 1.41

Database version: 2876

Windows 6.0.6001 Service Pack 1 (Safe Mode)

30/09/2009 12:06:37

mbam-log-2009-09-30 (12-06-37).txt

Scan type: Quick Scan

Objects scanned: 81259

Time elapsed: 6 minute(s), 13 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Windows\win32k.sys (Trojan.Dropper) -> Quarantined and deleted successfully.

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.