Hello.

For one or two of our Windows XP Home Edition profiles (too many kids), but not all profiles, we've been getting a Windows Defender Warning stating WD has "detected programs that might compromise privacy or damage our computer." It names "TrojanDownloader:Win32/Renos.DZ." Paired with this is a 'b.exe' message stating b.exe 'has encountered a problem and needs to close". And, once in a while, we get a "CiceroUIWndFrame: b.exe - Application Error" stating 'the exception unknown software exception (0xe06d7363) occurred in the application at location 0x7c812afb' and/or a "b.exe Application Error" stating the 'instruction at 0x7c910cbd referenced memory at 0x69766f6d. The memory could not be 'read'.'

Our internet (Mozilla) is very slow.

Reading a few threads, I've downloaded MBAM and HJT, scanned, removed threats, and attached logs. Note: when I rebooted after running MBAM (to complete threat removal), the warning and error messages popped-up as if I'd done nothing.

Any help would be appreciated.

Thanks.

Dani AI

Generated

A short expert summary and next steps (grounded in what you already did)

The Windows Defender label TrojanDownloader:Win32/Renos.DZ plus a transient b.exe in a Temp path is typical of a downloader that unpacks/runs from a per-user temporary folder. Defender/antimalware engines often show a “(UPX)” hint when a sample is packed; packed downloaders commonly crash or throw a Visual C++ exception (the 0xE06D7363 code you saw) when a payload misbehaves or is partially removed. Defender will often quarantine or delete the Temp copy, which explains why b.exe may vanish after cleanup. (microsoft.com)

What to do next (safe, non-destructive checks)

  1. Enumerate autostarts for every user with Autoruns (it shows Run/RunOnce, scheduled tasks, services, Winsock providers, BHOs, etc.). Run it as admin, save the full output (File → Save) and look under the User menu for each profile — this will reveal persistent pieces left behind even after Defender cleans a temp dropper. Don’t restore quarantined items; just disable/uncheck unknown third‑party entries and save the Autoruns snapshot for review. (learn.microsoft.com)

  2. Collect Defender history/event details (threat name, path, date/time) and pair those timestamps with an Autoruns snapshot. If possible, note the exact detection name and the event IDs (Defender logs include actions like Quarantine/Delete) so a volunteer can correlate removals vs persistent entries. (learn.microsoft.com)

When a live scan isn’t enough

Boot the machine from a clean USB/CD rescue environment and run a full offline scan (this finds hidden/rootkit components and files that live on disk but don’t show when Windows is running). Kaspersky Rescue Disk is one example widely used for this purpose; build the media from a known-clean PC, update signatures on the rescue environment, then scan the infected drive. After offline removal, re-run Autoruns and Defender to confirm nothing persists. (support.kaspersky.com)

Final notes

As noted, startup persistence is the usual cause; ’s Vundo checks and ’s cleanup ideas are reasonable early steps. If the Autoruns output or Defender events still show active entries after offline scans, collect and post the Autoruns saved file plus the Defender event timestamps so responders can point to specific entries. If removal is not certain, a clean OS reinstall on an unsupported XP system (no longer supported by Microsoft) is the safest long-term fix. (en.wikipedia.org)

Recommended Answers

All 5 Replies

First of all, it would seem you have a Trojan Virus. It would also seem that it is re-running itself at startup. Whatever anti-virus you are using is not getting rid of it. When your anti-virus finds it, it should include a path. Attempt to navigate to that path and delete the program manually. This b.exe if part of the Trojan Virus, the fact that there is an error may mean that the one who coded the virus was not a very good coder -.-.
But anyway try deleting the file manually/ending the process via task manager (can be opend with ctrl+shift+escape or ctrl+alt+delete -> Open Task Manager) If you don't know how to do that, go to the process tab and look for b.exe, select it and press end task (as well as Trojan.exe is you find it).
I hope that helps.

this line in the logs you provided:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\6c153f40 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
May mean that you have the "deadly" Trojan Vundo, which is Extremely hard to get rid of.

Please download VundoFix.exe to your Desktop.

* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* It will make a log in C:\vundofix.txt, I need you to post that in your next reply.

Hi.

I downloaded VundoFix and ran it in on our Administrator profile and again in the profile that has the most problems (just in case it mattered) and it found no infections either time. I've attached the log per your request.

Today, we have not yet seen the b.exe application error message, but we still have the TrojanDownloader:Win32/Renos.DZ warning.

I can't find the path that u8sand recommends because the file associated with the TrojanDownloader warning, which is C:\Documents and Settings\email\Local Settings\temp\b.exe->(UPX), did not exist. Of course, I looked only after asking Windows Defender to fix the problem, but we've done that many many times already.

How can we be sure we don't have the Vundo virus?

How can we make sure the b.exe TrojanDownloader problem goes away and stays away?

Thanks.

Please do not Attach any logs, copy the content and paste it in your post..

Considering the infections are from the temp folders, as a preliminary measure do the following :

Download , Install it, Open it...
Under the 'Cleaner' Section select all in the 'Windows' And 'Applications' Tab, Then click on 'Analyze' And then 'Run Cleaner'...
Do The Same In The 'Registry' Tab, i.e. 'Scan For Issues' and 'Fix Selected Issues', It will ask you to make a backup, DO IT...Then Click on 'Fix All'...Now Reboot The Pc..

Now

Please download by sUBs...
* You must download it to and run it from your Desktop
* Physically disconnect from the internet.
* Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
* Double click combofix.exe & follow the prompts.
* When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
* Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

Upload The Combofix Log And a New Hijackthis Log(Reboot and then run hijackthis scan)..

what to do if my computer doesnt allow use of internet, cannot open antivirus, cannot e mail cannot recognize printer etc.. to get rid of trojan above

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.