WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionWin32/Renos.js EmptyWin32/Renos.js

more_horiz
Hello,
I am encountered with Rono.JS

It has disabled all my virus scanners and will not allow me to run them and not even in safe mode.

I am running Vista SP2 32-bit.

It is slowing down my computer, and having popup internet pages.

Please help me,
Thanks! Thank You!

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Please download ComboFix Win32/Renos.js Combofix from BleepingComputer.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
  • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.


I would also like to see a list of installed programs, so please do this:
Click Start > Run then copy/paste the following single-line command into the Run box and click OK:

C:\Qoobox\Add-Remove Programs.txt

In your next reply, please include the ComboFix log and the Add-Remove Programs log.

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
C:\ComboFix.txt
Spoiler :


C:\Qoobox\Add-Remove Programs.txt
Spoiler :


C:\ComboFix.txt
C:\Qoobox\Add-Remove Programs.txt

Thank you so much!

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:


    :filefind
    cngaudit.dll


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Win32/Renos.js DXwU4
Win32/Renos.js VvYDg

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Systemlook.txt

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    FCopy::
    C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll | C:\Windows\system32\cngaudit.dll

  4. Save this as CFScript.txt, in the same location as ComboFix.exe

    Win32/Renos.js Cfscriptb4i

  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Win32/Renos.js DXwU4
Win32/Renos.js VvYDg

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
C:\ComboFix.txt

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u

Win32/Renos.js CF_Cleanup

This will also reset your restore points.

How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Win32/Renos.js DXwU4
Win32/Renos.js VvYDg

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
It still does not let me run any anti-virus pogram.

And also sometimes it says rootkey was detected.

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Hmm, there is times where I've seen rootkits even Combofix can't pick up.

Download the GMER rootkit scan from here: GMER

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Win32/Renos.js DXwU4
Win32/Renos.js VvYDg

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
Spoiler :

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
That looks okay, no rootkit activity found.

Run ESET Online Scan
Please do an online scan with ESET Online Scanner. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Uncheck (untick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Win32/Renos.js DXwU4
Win32/Renos.js VvYDg

descriptionWin32/Renos.js EmptyRe: Win32/Renos.js

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum