Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan-Spy.Banker.EGJ  (Read 5745 times)

0 Members and 1 Guest are viewing this topic.

witsend

  • Guest
Trojan-Spy.Banker.EGJ
« on: November 18, 2007, 11:36:02 AM »
I have tried everything to get this off the computer.  I have Spy-doctor and it finds it and "removes" but it shows up again immediately.  I have DesktopMaestro and it finds three Temp files that I ast to remove but thsy show up again...I think they may be related...temp\~DFA7D2.tmp...DFC6B8.tmp and DFC5A2B3.tmp

I tried to download the hacker program that was suggested on this site..change name and run it...It would not let it run saying that win32 cannot run this program.

Also I will get a message that cannot connect to server 127.0.0.1...I read that this is my computer...can someone be intercepting??

It started with a Trojan-downloader.JS.Agent.abz infection.

Whats more when I try to get help Microsoft explorer closes the program---so I hope this goes through.

I am at my "witsend"

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Trojan-Spy.Banker.EGJ
« Reply #1 on: November 18, 2007, 11:37:19 AM »
Welcome to Computer Hope

HijackThis

Download HijackThis  to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file.
In your post, add the log as an Attachment.

* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Adding logs as an attachment

Save the log to somewhere you can easily find it. (usually the desktop)

To do this, from within the notepad go to the top of the page and select "File" > "Save As..." enter the file name and click "Save" Be sure the desktop is the location selected to save to.
Please save all files as Text Documents (.txt)

Posting the log

* Before putting text into the reply box select "Preview"
* Scroll down and select "Additional Options..."
* Click "Browse"
* Locate the file you want to attach and double click it to enter it into the window.
* If you have more than one log click "(more attachments)" and a new window will open for adding another log.
* You will need to enter a short message in the text box as well.

witsend

  • Guest
Re: Trojan-Spy.Banker.EGJ
« Reply #2 on: November 18, 2007, 12:02:43 PM »
I don't know if I attached this right or not
witsend :'(

[saving disk space - old attachment deleted by admin]

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Trojan-Spy.Banker.EGJ
« Reply #3 on: November 18, 2007, 12:20:23 PM »
What document did you save the log in? They should open in Notepad so please use that.

The log isn't showing any signs of malware but we can do a more thorough scan.

Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter at the prompt)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall



witsend

  • Guest
Re: Trojan-Spy.Banker.EGJ
« Reply #4 on: November 18, 2007, 04:57:49 PM »
here it is

[saving disk space - old attachment deleted by admin]

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Trojan-Spy.Banker.EGJ
« Reply #5 on: November 18, 2007, 05:01:34 PM »
Are the logs opening in Notepad?

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Trojan-Spy.Banker.EGJ
« Reply #6 on: November 18, 2007, 05:32:50 PM »
Please download ATF Cleaner by Atribune. ATF Cleaner.exe This program does not require an installation. The executable actually runs the program.

NOTE: ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
* Double-click ATF-Cleaner.exe to run the program.
* Under Main choose: Select All
* Click the Empty Selected button.

If you use Firefox browser
* Click Firefox at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
* Click Opera at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main ATF Cleaner menu to close the program.

==========

Use the  ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post.