Trojan-BNK.Win32.Keylogger.gen manual removal:
Delete registry values:HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command ??(Default)?? = ??av.exe?? /START ??%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command ??(Default)?? = ??av.exe?? /START ??%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command ??(Default)?? = ??av.exe?? /START ??%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command ??(Default)?? = ??av.exe?? /START ??%1? %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command ??(Default)?? = ??av.exe?? /START ??firefox.exe??
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command ??(Default)?? = ??av.exe?? /START ??firefox.exe?? -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command ??(Default)?? = ??av.exe?? /START ??iexplore.exe??
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ??AntiVirusOverride?? = ??1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ??FirewallOverride?? = ??1?
Delete files:av.exe WRblt8464P
Delete directories:%Documents and Settings%\[UserName]\Application Data\
Let me know if you figure out how to do this
Thank you for information
However AI do have qcg.exe" -a "%1"%*
Can I delete that?
damn thing wont even let us open the regedit command...any ideas??
i had to kill pdn.exe Process in task manager before i was able to access Malbytes...hope this helps someone!
Found file: C:Documents and SettingsRALAZARLocal SettingsApplication DataFRT.EXE which I deleted after killing the process of the same name.
I didnt delete the folder listed above.
The MalwareBytes download didnt work when run as a Administrator.
Instead of av.exe, it manifested as unm.exe on machine (XP)
I did not delete the Application Data directory.
I rebooted in Safe Mode, zapped the registry keys listed above, but
not all were present, and additional ones have been added.
In regedit I looked for all keys and values containing unm.exe and deleted them.
That worked for me. Thanks again.
C:Documents and Settings[user name]Local SettingsApplication Data BJE.EXE
which I deleted after killing the process of the same name.
The messages were from "XP security centre 2012"
cant do system restore
cant do add remove programs
A tech friend identified it as rootkit virus. I downloaded this
http://support.kaspersky.com/viruses/solutions?qid=208280684
and it was remedied in a few minutes. Then I ran Malewarebytes anti-virus, vaporized 6 related downloader trojans. Hope that helps someone.
Thanks Mike - for the excellent restore process tip and for allowing me to deal with the Trojan virus elimination - quickly and effectively. Much appreciated.
Thanks Mike - for the excellent restore process tip and for allowing me to deal with the Trojan virus elimination - quickly and effectively. Much appreciated.
Finally....anti-spyware found NOTHING. AND I could NOT run anything else or a Systems Restore! So I tried booting in safe mode again & one of the options was "Repair Computer", so, I clicked on it! There was a list of things to do & one was Systems Restore! I had to go back to Nov.29. Now I am able to run my security! Super anti spyware found one threat & removed it. Malwarebytes found one & removed!
Here it is the day after & everything seems fine! So if you cant do a systems restore.....try safe mode & then look at the list & click on "Computer Repair & then on systems repair....it WORKED!!!
http://deletemalware.blogspot.com/2011/06/remove-xp-antispyware-2012-xp-internet.html
Make sure that you can see hidden and operating system protected files in Windows. Go into C:Documents and Settings[UserName]Local SettingsApplication Data folder. Make sure you change user name! In the box that opens scroll down until you find the exe file. Mine was the qcg file and it has Russian words, so go figure, thats where it comes from. Change the name to virus.exe, save it, then restart your pc. After a restart, copy all the text in bold below and paste to Notepad.
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT.exe]
@="exefile"
"Content Type"="application/x-msdownload"
Save file as fix.reg to your Desktop. NOTE: (Save as type: All files) . Double-click on fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK. Run a full system scan with your favorite antivirus program. (2 on mine did not find anything). I went back in and deleted the renamed file and it seems to be gone. Best of luck.
6. Open Internet Explorer. Download xp_exe_fix.reg and save it to your Desktop. Double-click on xp_exe_fix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.
First run, got an error - wouldnt restore; Id just installed a new monitor from Christmas, so it didnt recognize the hardware change.
Started System Restore again, but unplugged the monitor immediately. Let restore finish, came back in 10 minutes and plugged it back in, restore worked. Had to set up monitor again, but no more virus.
Post Comment: