Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91681 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Resolved] trojan:win32/renos.n


  • This topic is locked This topic is locked
112 replies to this topic

#61 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 01:43 PM

if i try to download anything to computer. sometimes it will show in recent items and then when i try to open it from there, windows browses to find it and can't.

    Advertisements

Register to Remove


#62 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 06 October 2009 - 03:12 PM

press the Print Screen key It may be labeled [PrtScn]. - an image of your entire screen is copied to the clipboard.

Now open up your Microsoft Paint program

Go to the Edit menu and choose Paste.

If prompted to enlarge the image, choose Yes.

Go to the File Menu and choose Save As.

Navigate to the folder where you want to save the image. Try "My Pictures"

Type a file name for the image.

Now when you post it in your reply - you will need to upload the image:

step by step instructions are here



Are you able to navigate to this folder

c:\users\Jennifer\Downloads\ - tell me what programs you find there



NEXT

Please do the following:

Navigate to :

C:\Users\Jennifer\Desktop
Right Click on >Desktop
click >Properties
click >Security
What is set for ALLOW?

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#63 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 06:43 PM

everything is checked "allow" except special permissions

Attached Thumbnails

  • desktop.jpg


#64 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 06 October 2009 - 06:47 PM

Hi,

I have something else I would like you to do.

The following tool does not need to be saved.

Use Internet explorer, then click on the link and choose to run the tool:

exe_fix

you will be given an option box...choose option 1 - it will produce a log > acls.txt on your desktop...post the content.



NEXT:


Again using Internet Explorer

click on the following link:


http://noahdfear.net...ab_avg_free.exe


choose to run the tool...a small black command window will open.. The tool will automatically download the AVG installer...when it is done and asks you to 'press any key' press enter...

now the installer will download the necessary files, when it is done you will get a message, > press enter again.

Now the tool will automatically download to your desktop and launch.

click through the first few screens

it will check the status of the current installation and if valid, will present you with options to Install, Modify and Remove

select Remove


Let me know if it is successful

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#65 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 08:08 PM

neither of those worked. i clicked "run" and the run or save box disappears. nothing new on desktop. searched for acls.txt-nothing.

#66 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 06 October 2009 - 08:32 PM

Hi,

Please do the following:

Click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.

now paste the following command at the command prompt

assoc >"%userprofile%\desktop\assoc.txt"

hit enter

post the contents of assoc.txt on the desktop


then type the following command at the command prompt

set >"%userprofile%\desktop\set.txt"

hit enter

and post set.txt

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#67 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 08:59 PM

ok, done.

#68 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 06 October 2009 - 09:09 PM

Please post the contents of assoc.txt and set.txt those files should be on your desk top. they will open with notepad, copy and paste them into the thread

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#69 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 09:11 PM

.386=vxdfile .3g2=QuickTime.3g2 .3gp=QuickTime.3gp .3gp2=QuickTime.3gp2 .3gpp=QuickTime.3gpp .aac=QuickTime.aac .ac3=QuickTime.ac3 .aca=Agent.Character.2 .acf=Agent.Character.2 .acrobatsecuritysettings=AcroExch.acrobatsecuritysettings .acs=Agent.Character2.2 .adts=QuickTime.adts .aif=iTunes.aif .aifc=iTunes.aifc .aiff=iTunes.aiff .air=AIR.InstallerPackage .amc=QuickTime.amc .ani=anifile .ape=DMCConvert .api=AcroExch.Plugin .application=Application.Manifest .appref-ms=Application.Reference .ARC=WinZip .ARJ=WinZip .asa=aspfile .asf=NeroShowTime.Files.asf .asp=aspfile .asx=WMP11.AssocFile.ASX .au=WMP11.AssocFile.AU .avgdx=AvgDiagExFile .avi=NeroShowTime.Files.avi .avs=NeroShowTime.Files.avs .B64=WinZip .bat=batfile .BHX=WinZip .blg=PerfFile .bmp=Paint.Picture .bup=NeroShowTime.Files.bup .c2c=CopyToCD/DVD Project .c2r=MediaCenter.C2R .cab=WinZip .camp=campfile .cat=CATFile .cda=iTunes.cda .cdc=NeroCDCoverType .cdda=iTunes.cdda .cdmp=cdmpfile .cdx=aspfile .cer=CERFile .cfxxe=cfxxefile .ChessTitansSave-ms=MicrosoftChessTitansSaveFile .chk=chkfile .chm=chm.file .cmd=cmdfile .com=ComFile .ComfyCakesSave-ms=MicrosoftComfyCakesSaveFile .compositefont=Windows.CompositeFont .contact=contact_wab_auto_file .cpl=cplfile .crd=Microsoft.InformationCard .crds=Microsoft.WindowsCardSpaceBackup .crl=CRLFile .crt=CERFile .css=CSSfile .CTT=MessengerContactList .cur=curfile .CUT=NeroPhotoSnapViewer.Files.cut .dat=NeroShowTime.Files.dat .db=dbfile .DDS=NeroPhotoSnapViewer.Files.dds .der=CERFile .desklink=CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} .dib=Paint.Picture .dif=QuickTime.dif .disabled=SpybotSD.DisabledFile .divx=divxFile .dll=dllfile .doc=ooostub.DocDocument.1 .dot=ooostub.DotTemplate.1 .download=Safari Download .drv=drvfile .dsn=MSDASQL .dv=QuickTime.dv .DVR=MediaCenter.DVR .dvr-ms=NeroShowTime.Files.dvr-ms .dwfx=XPSViewer.Document .emf=emffile .eml=Microsoft Internet Mail Message .evt=evtfile .evtx=evtxfile .exe=exefile .fdf=AcroExch.FDFDoc .flac=DMCConvert .fnd=fndfile .fon=fonfile .FreeCellSave-ms=MicrosoftFreeCellSaveFile .gadget=Windows.gadget .gif=NeroPhotoSnapViewer.Files.gif .gmmp=gmmpfile .group=group_wab_auto_file .grp=MSProgramGroup .gz=WinZip .H1C=h1cfile .H1D=h1dfile .H1F=h1ffile .H1H=h1hfile .H1K=h1kfile .H1Q=h1qfile .H1S=h1sfile .H1T=h1tfile .H1V=h1vfile .H1W=h1wfile .HeartsSave-ms=MicrosoftHeartsSaveFile .hlp=hlpfile .hqx=WinZip .hta=htafile .htm=htmlfile .html=htmlfile .icc=icmfile .icl=IconLibraryFile .icm=icmfile .ico=NeroPhotoSnapViewer.Files.ico .ics=WindowsCalendar.FileIcs.1 .IFF=NeroPhotoSnapViewer.Files.iff .ifo=NeroShowTime.Files.ifo .inf=inffile .ini=inifile .ipa=iTunes.ipa .ipg=iTunes.ipg .ipsw=iTunes.ipsw .itb=iTunes.itb .itdb=iTunes.itdb .itl=iTunes.itl .itms=iTunes.itms .itpc=iTunes.itpc .jar=jarfile .jfif=NeroPhotoSnapViewer.Files.jfif .JNG=NeroPhotoSnapViewer.Files.jng .jnlp=JNLPFile .jnt=jntfile .Job=JobObject .jod=Microsoft.Jet.OLEDB.4.0 .jpe=jpegfile .jpeg=jpegfile .jpg=jpegfile .js=JSFile .JSE=JSEFile .jtp=jtpfile .jtx=XPSViewer.Document .key=regfile .KOA=NeroPhotoSnapViewer.Files.koa .label=Label .LBM=NeroPhotoSnapViewer.Files.lbm .lnk=lnkfile .log=txtfile .lwv=lwvfile .LZH=WinZip .m1v=NeroShowTime.Files.m1v .m2a=DMCConvert .m2p=NeroShowTime.Files.m2p .m2t=NeroShowTime.Files.m2t .M2V=NeroShowTime.Files.m2v .m3u=iTunes.m3u .m3u8=iTunes.m3u8 .m4a=iTunes.m4a .m4b=iTunes.m4b .m4p=iTunes.m4p .m4r=iTunes.m4r .m4v=iTunes.m4v .mac=QuickTime.mac .MahjongTitansSave-ms=MicrosoftMahjongTitansSaveFile .mapimail=CLSID\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} .mbam=mbam.script .mcl=MediaCenter.MCL .mfp=MacromediaFlashPaper.MacromediaFlashPaper .mht=mhtmlfile .mhtml=mhtmlfile .mid=NeroShowTime.Files.mid .midi=NeroShowTime.Files.midi .mig=migfile .MIM=WinZip .MinesweeperSave-ms=MicrosoftMinesweeperSaveFile .mlc=LpkSetup.1 .MNG=NeroPhotoSnapViewer.Files.mng .MOD=WMP11.AssocFile.MPEG .mov=QuickTime.mov .mp1=DMCConvert .mp2=iTunes.mp2 .mp2v=WMP11.AssocFile.MPEG .mp3=iTunes.mp3 .mp4=QuickTime.mp4 .mpa=NeroShowTime.Files.mpa .mpc=DMCConvert .mpe=WMP11.AssocFile.MPEG .mpeg=NeroShowTime.Files.mpeg .mpg=NeroShowTime.Files.mpg .mpga=DMCConvert .mpv2=WMP11.AssocFile.MPEG .mpx=DMCConvert .mqv=QuickTime.mqv .msc=MSCFile .msdm=MsdtManifest .msdvd=Windows.DVD.Maker .msi=Msi.Package .msp=Msi.Patch .msrcincident=RemoteAssistance.1 .msstyles=msstylesfile .msu=Microsoft.System.Update.1 .MSWMM=Windows.Movie.Maker .mydocs=CLSID\{ECF03A32-103D-11d2-854D-006008059367} .nbi=NBBACKUPType .ncd=Nero Cover Designer.Document .nco=NBCOMPRESSType .nct=Nero Cover Designer.Template .nfo=MSInfoFile .nhf=NeroHFSType .nhv=NeroHDBVideoType .nji=NBJOBType .nmd=NerominiDVDType .nr3=NeroMP3Type .nra=NeroAudioType .nrb=NeroCDROMBootType .nrc=NeroUDFISOType .nrd=NeroDVDVideoType .nre=NeroCDExtraType .nrg=NeroImageType .nrh=NeroCDROMHybridType .nri=NeroCDROMType .nrm=NeroMixedModeType .nrs=NeroCDROMEFIBootType .nru=NeroUDFType .nrv=NeroVideoType .nrw=NeroWMAType .nsd=NeroSuperVideoType .nvc=NeroVision.Document .nws=Microsoft Internet News Message .ocx=ocxfile .odb=ooostub.DatabaseDocument.1 .odf=ooostub.MathDocument.1 .odg=ooostub.DrawDocument.1 .odm=ooostub.WriterGlobalDocument.1 .odp=ooostub.ImpressDocument.1 .ods=ooostub.CalcDocument.1 .odt=ooostub.WriterDocument.1 .ogg=DMCConvert .otf=otffile .otg=ooostub.DrawTemplate.1 .oth=ooostub.WriterWebTemplate.1 .otp=ooostub.ImpressTemplate.1 .ots=ooostub.CalcTemplate.1 .ott=ooostub.WriterTemplate.1 .oxt=ooostub.Extension.1 .p10=P10File .p12=PFXFile .p7b=SPCFile .p7c=certificate_wab_auto_file .p7m=P7MFile .p7r=P7RFile .p7s=P7SFile .pbk=pbkfile .pcast=iTunes.pcast .PCD=NeroPhotoSnapViewer.Files.pcd .pct=QuickTime.pct .PCX=NeroPhotoSnapViewer.Files.pcx .pdf=AcroExch.Document .pdfxml=AcroExch.pdfxml .pdx=PDXFileType .pfm=pfmfile .pfx=PFXFile .pic=QuickTime.pic .pict=QuickTime.pict .pif=piffile .pko=PKOFile .plist=QuickTimePreferences .pls=iTunes.pls .pms=Pro.Media.Director .pnf=pnffile .png=NeroPhotoSnapViewer.Files.png .pnt=QuickTime.pnt .pntg=QuickTime.pntg .pot=ooostub.PotTemplate.1 .pps=ooostub.PpsDocument.1 .ppt=ooostub.PptDocument.1 .prf=prffile .psd=NeroPhotoSnapViewer.Files.psd .PurblePairsSave-ms=MicrosoftPurblePairsSaveFile .PurbleShopSave-ms=MicrosoftPurbleShopSaveFile .qds=SavedDsQuery .qht=QuickTime.qht .qhtm=QuickTime.qhtm .qpa=QuickTimePlayerAddition .qt=QuickTime.qt .qti=QuickTime.qti .qtif=QuickTime.qtif .qtl=QuickTime.qtl .qtp=QuickTimePreferences .qtr=QuickTimeResources .qts=QuickTimeSystem .qtx=QuickTimeExtension .ra=DMCConvert .rat=ratfile .RDP=RDP.File .reg=regfile .rle=rlefile .rll=dllfile .rmf=AcroExch.RMFFile .rmi=NeroShowTime.Files.rmi .rtf=rtffile .sbe=SpybotSD.SBEFile .sbi=SpybotSD.SBIFile .sbs=SpybotSD.SBSFile .scf=SHCmdFile .scp=txtfile .scr=scrfile .sct=scriptletfile .sd2=QuickTime.sd2 .search-ms=SearchFolder .secstore=AcroExch.SecStore .sfcache=EMDFileProperties.1 .shn=DMCConvert .shtml=shtmlfile .slupkg-ms=MSSLPUFile .snd=WMP11.AssocFile.AU .SolitaireSave-ms=MicrosoftSolitaireSaveFile .spc=SPCFile .SpiderSolitaireSave-ms=MicrosoftSpiderSolitaireSaveFile .spl=ShockwaveFlash.ShockwaveFlash .sst=CertificateStoreFile .stc=ooostub.StarCalcTemplate.6 .std=ooostub.StarDrawTemplate.6 .sti=ooostub.StarImpressTemplate.6 .stl=STLFile .stw=ooostub.StarWriterTemplate.6 .swf=ShockwaveFlash.ShockwaveFlash .sxc=ooostub.StarCalcDocument.6 .sxd=ooostub.StarDrawDocument.6 .sxg=ooostub.StarWriterGlobalDocument.6 .sxi=ooostub.StarImpressDocument.6 .sxm=ooostub.StarMathDocument.6 .sxw=ooostub.StarWriterDocument.6 .sys=sysfile .tar=WinZip .TAZ=WinZip .tga=NeroPhotoSnapViewer.Files.tga .tgz=WinZip .theme=themefile .tif=NeroPhotoSnapViewer.Files.tif .tiff=NeroPhotoSnapViewer.Files.tiff .tnfo=SpybotSD.TInfoFile .torrent=Azureus .trp=NeroShowTime.Files.trp .ttc=ttcfile .ttf=ttffile .txt=txtfile .TZ=WinZip .UDL=MSDASC .url=InternetShortcut .uti=SpybotSD.UTIFile .uts=SpybotSD.UTSFile .UU=WinZip .UUE=WinZip .VBE=VBEFile .vbs=VBSFile .vcf=vcard_wab_auto_file .vob=NeroShowTime.Files.vob .vuze=Vuze .vxd=vxdfile .wab=wab_auto_file .wav=iTunes.wav .wave=iTunes.wave .wax=WMP11.AssocFile.WAX .wbcat=wbcatfile .WBM=NeroPhotoSnapViewer.Files.wbm .WBMP=NeroPhotoSnapViewer.Files.wbmp .wcinv=MSWinCollab .wcinv-ms-p2p=MSWinCollab .wdp=wdpfile .WebAllowBlockList=WebAllowBlockList_wpc .webpnp=webpnpFile .wlcshrtctv2=LiveCall .wm=WMP11.AssocFile.ASF .wma=NeroShowTime.Files.wma .WMD=WMP11.AssocFile.WMD .wmdb=WMP.WMDBFile .wmf=NeroPhotoSnapViewer.Files.wmf .WMS=WMP11.AssocFile.WMS .wmv=NeroShowTime.Files.wmv .wmx=WMP11.AssocFile.ASX .wmz=WMP11.AssocFile.WMZ .WPL=WMP11.AssocFile.WPL .wsc=scriptletfile .WSF=WSFFile .WSH=WSHFile .wtx=txtfile .wv=DMCConvert .wvx=WMP11.AssocFile.WVX .xaml=Windows.XamlDocument .xbap=Windows.Xbap .XBM=NeroPhotoSnapViewer.Files.xbm .xdp=AcroExch.XDPDoc .xfdf=AcroExch.XFDFDoc .xht=xhtfile .xhtml=xhtmlfile .xls=ooostub.XlsDocument.1 .xlt=ooostub.XltTemplate.1 .xlw=ooostub.XlwDocument.1 .xml=xmlfile .xps=XPSViewer.Document .xrm-ms=MSSLLFile .xsl=xslfile .XXE=WinZip .ymg=YPager.Messenger .yps=YPager.Messenger .z=WinZip .zfsendtotarget=CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} .zip=WinZip ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Jennifer\AppData\Roaming CLASSPATH=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=CRAPHEAP ComSpec=C:\Windows\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Jennifer LOCALAPPDATA=C:\Users\Jennifer\AppData\Local LOGONSERVER=\\CRAPHEAP NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\Program Files\QuickTime\QTSystem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 3, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0403 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files PROMPT=$P$G PUBLIC=C:\Users\Public QTJAVA=C:\Program Files\Java\jre6\lib\ext\QTJava.zip SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\Jennifer\AppData\Local\Temp TMP=C:\Users\Jennifer\AppData\Local\Temp USERDOMAIN=crapheap USERNAME=Jennifer USERPROFILE=C:\Users\Jennifer windir=C:\Windows

#70 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 06 October 2009 - 09:25 PM

Hi,

Please right click the following link

http://noahdfear.net...ab_avg_free.exe

choose > save target as> then direct it to save on your desktop

if it successfully saves there...locate it > right click it and run it as administrator

click through the first few screens

it will check the status of the current installation and if valid, will present you with options to Install, Modify and Remove

select Remove

let me jnow if successful


next


were you able to navigate to the folder

c:\users\Jennifer\Downloads


tell me what that folder contains

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015

    Advertisements

Register to Remove


#71 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 09:41 PM

ok, had to save it twice but it is now on desktop..says not compatable with my system. downloads folder is a bunch of pictures, atfcleaner,combofix,hjtinstall,windowskb890830v2.13,mbam-setup,setup-hotbar installer-pinball corp-i have no idea what that is. created 9/24/09

#72 noahdfear

noahdfear

    Silver Member

  • Visiting Fellow
  • PipPipPip
  • 465 posts
  • MVP

Posted 06 October 2009 - 09:44 PM

Sorry for the intrusion.

says not compatable with my system


Please open a command window and type ver then hit Enter.
Let me know the results please.
Dave

#73 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 09:47 PM

version 6.0.6002

#74 noahdfear

noahdfear

    Silver Member

  • Visiting Fellow
  • PipPipPip
  • 465 posts
  • MVP

Posted 06 October 2009 - 09:53 PM

I've updated the file. Please grab a new copy and try again.
Dave

#75 entropy1120

entropy1120

    Authentic Member

  • Authentic Member
  • PipPip
  • 70 posts

Posted 06 October 2009 - 09:53 PM

this is the message i get when i try to uninstall AVG from control panel : Local machine: installation failed Initialization: Error: Connecting to item registry root HKCU (Mcx1) failed. Error 0x80070005

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users