The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Need Help removing a trojan

    Discussion in 'Security and Anti-Virus Software' started by umar, Dec 6, 2008.

  1. umar

    umar Notebook Evangelist

    Reputations:
    29
    Messages:
    405
    Likes Received:
    0
    Trophy Points:
    30
    ok so 3 days ago i download a video codec, now when i tried to install it, both Windows Defender and AVG anti virus said that it contained a trojan and a pop up enabler. So i deleted it and did a complete scan of my system with both Defender and AVG. They both found something and reoved it.
    But the thing is whenever i reboot my computer, Defender always gives a warning that trojan Renoz.dz is present. (sometimes AVG also gives a warning) Now i have rebooted my computer abt 10 times and selected remove when the warning pops up. But it still comes up when ever i restart the computer.

    And after the warning when i select delete, i do a complete system scan but nothing is detected. And the process repeats itself when i restart :(
     
  2. aan310

    aan310 Notebook Virtuoso

    Reputations:
    738
    Messages:
    3,811
    Likes Received:
    2
    Trophy Points:
    106
    boot into safe mode then run a scan.

    else google for a remover for that specific Trojan / instructions on removing
     
  3. royk50

    royk50 times being what they are

    Reputations:
    258
    Messages:
    1,975
    Likes Received:
    0
    Trophy Points:
    55
  4. ahl395

    ahl395 Ahlball

    Reputations:
    3,867
    Messages:
    8,218
    Likes Received:
    72
    Trophy Points:
    216
    Also try shredding the infected file. ;)

    I suggest Simple File Shredder or AxCrypt Shredder.
     
  5. bridge86

    bridge86 Notebook Consultant

    Reputations:
    0
    Messages:
    129
    Likes Received:
    0
    Trophy Points:
    30
    Make sure system restore is disabled because some viruses piggyback on it and restore themselves using system restore.

    Don't forget to turn it back on when the virus gone.
     
  6. Cape Consultant

    Cape Consultant SSD User

    Reputations:
    153
    Messages:
    1,149
    Likes Received:
    1
    Trophy Points:
    55
    I second royk50.
     
  7. nizzy1115

    nizzy1115 Notebook Prophet

    Reputations:
    2,557
    Messages:
    6,682
    Likes Received:
    1
    Trophy Points:
    205
    I also agree on malwarebytes. It is a phenomenal program.
     
  8. Daemos

    Daemos Notebook Enthusiast

    Reputations:
    1
    Messages:
    47
    Likes Received:
    0
    Trophy Points:
    15
    try Avast antivirus, it's free, and it's pretty powerful. Hopefully it doesn't resort to a format/reinstall =(
     
  9. entropy.cz

    entropy.cz Notebook Evangelist

    Reputations:
    110
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    in order to remove it properly, it's good to know
    - where is it (system volume information, temporary internet files, temp, windows\system32, ..., - where?)
    - when does it come back - if it does (after restart? what if you restart when the internet is unplugged?)
    - what is the filename and the threat name as detected by avg?
    - what will scanning in the safe mode do? sometimes trojans are held by running processes and therefore cannot be deleted in normal mode
    - try using ccleaner to see what's on the startup list... the trojan or its part will most probably sit there

    and after you get rid of it, you'll know that you should never ever launch anything you don't know or are not absolutely sure about. :rolleyes:
     
  10. Deks

    Deks Notebook Prophet

    Reputations:
    1,272
    Messages:
    5,201
    Likes Received:
    2,073
    Trophy Points:
    331
    The best way to remove persistent pests from the OS is to boot into safe-mode and scan the system via antivirus from there.

    I also recommend Spybot.
    Download it, update it, re-boot into safe-mode, scan the system with your antivirus first, then with Spybot.
    Clean out anything that is found, and you should be good.
    :)
     
  11. kanehi

    kanehi Notebook Deity

    Reputations:
    146
    Messages:
    1,943
    Likes Received:
    0
    Trophy Points:
    55
    Some of those trojans are very difficult to remove. They embed themselves to start automatically when your system starts. They are also difficult to find because they are named like they are part of Windows OS and will even go into the Registry. My friend caught one of these viruses and had to reinstall his system.
     
  12. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    To be sure that Malwarebytes'Antimalware (or any other program you used) has succesfully removed the trojan, follow the instructions on one of these fora; BleepingComputer or MajorGeeks.
    Follow every step recommended, only then you can be sure you're clean.