TrojanSpy:MSIL/Bank...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

[Closed] TrojanSpy:MSIL/Banker.J - I can't get it off my pc

13 Posts
11 Users
0 Reactions
124 Views
 hora
Posts: 0
Free Member
Topic starter
 

Help(?) Googling it it looks like a financial virus. I've used the microsoft virus checker on my pc- finds/quarantees it but the next morning when I'm tabbing through the keys I notice a new icon "My Document" which means I'll try/its located and 'cleaned' again.

Is there anything else I can do? Nuke the PC?

Source: I downloaded a job application zip for a friend yesterday


 
Posted : 20/12/2013 8:23 am
Posts: 0
Free Member
 

You've tried Malwarebytes yes ?


 
Posted : 20/12/2013 8:25 am
Posts: 251
Full Member
 

try malwarebytes instead


 
Posted : 20/12/2013 8:25 am
 hora
Posts: 0
Free Member
Topic starter
 

This one? : http://www.malwarebytes.org/lp/lp4/?gclid=CKPCh-ywvrsCFbGWtAodpBoA1Q

Will do


 
Posted : 20/12/2013 8:25 am
Posts: 77347
Free Member
 

Look for a registry entry at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OLE and delete it if it exists. This should stop it running on a reboot.

System restore to a point in time before the infection can sometimes be very effective (unless it's infected those too).

Other than that, as said, Malwarebytes is your first line of defence. Save the log it creates.

Look for krk.txt in your Windows folder. Assume that any text contained within is in the hands of the author and act accordingly with regards to passwords and bank accounts.

Assuming you've removed it, you may need to reset your browser to remove proxy settings and home page redirects. Exact instructions vary by browser. IE: http://support.microsoft.com/kb/923737


 
Posted : 20/12/2013 8:52 am
Posts: 2
Free Member
 

Some of these viruses are very carefully targeted. They know exactly who their victims are.

Are you sure it's 'Banker'? 😉


 
Posted : 20/12/2013 8:54 am
Posts: 3590
Free Member
 

Restart computer in safe mode before running virus / malware checker. And, as above, restore to pre-virus point.


 
Posted : 20/12/2013 8:57 am
Posts: 27
Full Member
 

Cougar, would you recommend malwarebytes and does it run alongside Microsoft Security Essentials? I've been running MacAfee until yesterday but uninstalled it as the real time scan protection kept turning itself off for some reason. I then installed MSE but I'm unsure if it's enough. I only use the laptop for university related work and general browsing. Any advice would be appreciated.


 
Posted : 20/12/2013 9:33 am
 hora
Posts: 0
Free Member
Topic starter
 

Thanks chaps. When I use alt tab key to navigate the 'My Document' icon is still showing (but then the virus scanner hasn't finished its scanning etc to clean.

See below- nothing stored in there is there?

Link http://www.flickr.com/photos/30625376@N06/11462422233/lightbox/

[img] [/img]


 
Posted : 20/12/2013 9:35 am
Posts: 25815
Full Member
 

[u][b]Malwarebytes[/b][/u] - Member
Objects detected: 81
Naughty Hora ! 😀


 
Posted : 20/12/2013 9:41 am
Posts: 0
Free Member
 

System restore to a point in time before the infection can sometimes be very effective (unless it's infected those too).

worked for us when we got a virus (ironically one permanently trying to get us to download a supposed antivirus programme).


 
Posted : 20/12/2013 5:32 pm
Posts: 7167
Full Member
 

I had a Trojan on my laptop and running Spybot search and destroy as an administrator removed it , after AVG plus microsoft security essentials didnt even find it after a edep scan.
Might be worth a punt as its free


 
Posted : 20/12/2013 5:37 pm
Posts: 0
Free Member
 

81 !

Lay off the grumble for a while 😉


 
Posted : 20/12/2013 5:40 pm
Posts: 9763
Full Member
 

Try a virus scanner that boots of a memory stick and runs the PC of Linnux. AVG do one amongst others

But it was malware bytes that got mine in the end

It didn't scan for it. It got it be detecting the malicious action of the program when it executed in real time.


 
Posted : 20/12/2013 5:45 pm

6 DAYS LEFT
We are currently at 95% of our target!