This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

i am infected by W32/Renos.gen!C Rootkit ftdisk.sys,FakeHost

1 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from April 19, 2010, 5:18 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Pajajn
Hello everyone :compress:
Yesterday my F-secure told me that i was infected by trojan downloader and there was only a "ok" button, and the Window was in Windows 98:theme with Title "F-Secure Anti Virus"

Trojan.Downloader
W32\Renos.gen!C
Attacked:
C:\Windows\temp\"xxx".tmp\svchost.exe
xxx= name changes each time the file is downloaded :S

For about some hours ago i came up with a new window telling me that

Intrusion:
Rootkit.Patched.TDSS.Gen
Attacked:
C:\windows\system32\drivers\ftdisk.sys

Ive got IE7 and Service Pack 3 installed, and i noticed that when i have one IE opened,
the process name is "iexplorer.exe" but there is 2 processes open in taskmanager but only one in desktop :?: :shock:

I and my father need help as fast as possible :(
NonSuch Administrator
In order for us to help you it is necessary that you provide us with a HijackThis log. Please follow the guideline at the link below to start a new topic and post your HijackThis log by pasting it into your post. Do not utilize attachments.

Also note that this is a free, volunteer supported site. As such, help is given on a first come first served basis. If your situation is emergent and you cannot wait for help, then your best option is to take your computer into a trusted local shop and have the work done there.

This topic is now closed. Please start a new topic by following the HijackThis Guideline posted here: >Guideline for posting your HijackThis log<

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.