[Resolved] Renos.BAH problem
31 min read
My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
- I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through the instructions before starting to follow them to amek sure you understand everything you have to do.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
- Disable any script blocking protection
- Double click dds.scr to run the tool.
- When done two logs should open:
- DDS.txt
- Attach.txt
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please click Start >> Control Panel >> Add/Remove Programs. Find the following item on the list and click Remove.
Java™ SE Runtime Environment 6 Update 1
Open Windows Defender.
Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.
Please download OTMoveIt3 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=-
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
"{C4069E3A-68F1-403E-B40E-20066696354B}"=-
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars]
"{32683183-48a0-441b-a342-7c2a440a9478}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysWin"=-
[-HKEY_CLASSES_ROOT\{6a950a63-e31f-4794-8ddb-858ab1755a2d}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=-
:Commands
[emptytemp]
[Reboot] - Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt3
We need to upload a file to Jotti
1. Click HERE to get to Jotti's site.
2. At the top of the Jotti window, use the Browse button to locate the following file on your system:
C:\WINDOWS\fonts\wfonts.key
3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.
4. Please provide me with the results of the analysis.
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
- Click NO
- In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
- Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity. - Click OK.
- GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
- Save it where you can easily find it, such as your desktop.
Thanks.
Hmm, it should be rebooting the machine and then making the log. Try disabling SpyBot as well.
You need to disable TeaTimer, so that it doesn't interfere with our fix.
This is a two step process.
First step:
- Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
- If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
- If you have Version 1.4, Click on Exit Spybot S&D Resident
- Open Spybot S&D
- Click Mode, choose Advanced Mode
- Go to the bottom of the vertical panel on the left, click Tools
- Then, also in left panel, click Resident shows a red/white shield.
- If your firewall raises a question, say OK
- In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
- OK any prompts.
- Use File, Exit to terminate Spybot
- Reboot your machine for the changes to take effect.
Thanks.
No idea what's going on with OTMI3. I have notified the developer. We will plod on with a different route. I don't think the driver stuff is related, but we'll see.
Did you make a backup with ERUNT before starting this topic? If not, now is the time to do so. See instructions here if you need to:
http://forums.whatthetech.com/Welcome_New_…ers_t34502.html
Next, please do this:
- Copy the contents of the Code Box below to Notepad.
- Name the file as fix.reg
- Change the Save as Type to All Files
- and Save it on the desktop
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=-
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
"{C4069E3A-68F1-403E-B40E-20066696354B}"=-
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"=-
[-HKEY_CLASSES_ROOT\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}]
[-HKEY_CLASSES_ROOT\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}]
[-HKEY_CLASSES_ROOT\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
[-HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-HKEY_CLASSES_ROOT\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}]
[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars]
"{32683183-48a0-441b-a342-7c2a440a9478}"
[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysWin"=-
[-HKEY_CLASSES_ROOT\CLSID\{6a950a63-e31f-4794-8ddb-858ab1755a2d}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=-
[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]
Make sure there are NO blank lines before REGEDIT4, and a blank line at the end.Then right-click on the fix.reg file and click merge, say yes to any prompts.
Please reboot and then continue with my instructions from GMER onwards. I also want a fresh DDS log.
Thanks.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI