hi can someone please help...i hav the same problem wih this trojan.....i followed the renaming procedure but after my scan....no infected results came up....as soon as i restart back to normal mode.....the same thing happened...() came back with windows defender...this is my 1st quick scan log.....

Malwarebytes' Anti-Malware 1.12
Database version: 722

Scan type: Quick Scan
Objects scanned: 29987
Time elapsed: 2 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


i scanned it the 2nd time full scan.....

Malwarebytes' Anti-Malware 1.12
Database version: 722

Scan type: Full Scan (C:\|)
Objects scanned: 123635
Time elapsed: 17 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


then i tried in normal mode after the safe mode.....a quick scan...

Malwarebytes' Anti-Malware 1.12
Database version: 722

Scan type: Quick Scan
Objects scanned: 31574
Time elapsed: 4 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Dani AI

Generated

reported that Windows Defender keeps flagging Win32.Renos.dz after a clean-looking Malwarebytes scan. That pattern most often means the infection is using a persistence mechanism (registry Run keys, scheduled tasks, services, or a rootkit) so it relaunches on startup or hides from in-OS scanners. See the ATT&CK notes on registry/run persistence and Malwarebytes’ guidance on rootkits for background. (attack.mitre.org)

Recommended workflow (least to most disruptive):

  1. Update the anti-malware program and signature databases (as @jholland1964 advised), then run a full normal-mode scan.
  2. Disconnect the machine from the network to reduce reinfection risk.
  3. Run an offline/boot-time scan so the scanner runs outside the running OS (built-in Microsoft Defender Offline or a bootable rescue environment like ESET SysRescue). These scans can find files that are in use or hidden while Windows is running. (learn.microsoft.com)

If the problem persists after updated scans, investigate autostart points with Autoruns (Sysinternals). Run Autoruns as administrator, enable the option to hide Microsoft/Windows entries, then review Logon, Scheduled Tasks, Services, Drivers, Image Hijacks and AppInit DLLs. Use “Jump to Entry” to get the file path; uncheck to disable an entry first, delete only after confirming the backing file is malicious. Autoruns also offers VirusTotal integration for quick checks. (learn.microsoft.com)

A final note of caution: persistent or kernel-level infections (rootkits/bootkits) sometimes cannot be fully cleaned. If offline tools and manual removal cannot stop the file from reappearing, the safest path is a full backup of personal data followed by a clean OS install—some rootkits require that. Keep copies of scan logs and Autoruns exports for later analysis. (malwarebytes.com)

References:

Your Malwarebytes' Anti-Malware program is woefully way, way out of date. Current version is 1.37 and the database is 2227.

You need to update to the most current version and database. Then re-scan using NORMAL MODE ONLY and a FULL SYSTEM SCAN. Remove ALL items found.

Reboot the computer and then download and run on a Full System Scan. Save the log.
Post back here with the New MBA-M log and the HJT log.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.