Page 1 of 2 12 LastLast
Results 1 to 16 of 18

Thread: Can't seem to remove a trojan - help appreciated.

  1. #1
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Can't seem to remove a trojan - help appreciated.

    Hi all,

    Microsoft Malicious Software removal tool continually picks up this trojan on my PC:

    http://www.microsoft.com/security/po...2fBancos.gen!A

    Unfortunately I can't do anything about removing it.

    The tool itself won't remove it and I've run the windows livescan online virus remover but neither that, Spybot SD-Resident nor AVG can detect it on their scans.

    I'm not too worried about the effects of the trojan - apparantly it only keylogs a selection of brazillian banks - but I don't like having it there!

    Any suggestions? Equally, any idea how it could have got there? I use firefox's latest edition and have AVG and Spybot running all the time. I'm quick to patch when there's new updates available... Maybe it arrived before I had chance to install all of that?

    I'm using Windows Vista Business Edition SP1 running on a Dell laptop. Many thanks all!

  2. #2
    Mostly Me Lucio's Avatar
    Join Date
    Mar 2007
    Location
    Tring
    Posts
    5,163
    Thanks
    443
    Thanked
    448 times in 351 posts
    • Lucio's system
      • Motherboard:
      • Gigabyte GA-970A-UD3P
      • CPU:
      • AMD FX-6350 with Cooler Master Seldon 240
      • Memory:
      • 2x4GB Corsair DDR3 Vengeance
      • Storage:
      • 128GB Toshiba, 2.5" SSD, 1TB WD Blue WD10EZEX, 500GB Seagate Baracuda 7200.11
      • Graphics card(s):
      • Sapphire R9 270X 4GB
      • PSU:
      • 600W Silverstone Strider SST-ST60F
      • Case:
      • Cooler Master HAF XB
      • Operating System:
      • Windows 8.1 64Bit
      • Monitor(s):
      • Samsung 2032BW, 1680 x 1050
      • Internet:
      • 16Mb Plusnet

    Re: Can't seem to remove a trojan - help appreciated.

    Try www.malwarebytes.org's tool, it's been useful in the past for removing tricky viruses.

    (\___/) (\___/) (\___/) (\___/) (\___/) (\___/) (\___/)
    (='.'=) (='.'=) (='.'=) (='.'=) (='.'=) (='.'=) (='.'=)
    (")_(") (")_(") (")_(") (")_(") (")_(") (")_(") (")_(")


    This is bunny and friends. He is fed up waiting for everyone to help him out, and decided to help himself instead!

  3. #3
    jem
    jem is offline
    Registered User
    Join Date
    Oct 2008
    Posts
    0
    Thanks
    15
    Thanked
    1 time in 1 post

    Re: Can't seem to remove a trojan - help appreciated.

    Try a online scanner like pandasecurity,They are normally good.When scanning remember to do scans in safe mode and clear out the temporary internet folder/cookies

  4. #4
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.

    Thanks for both of those suggestions - unfortunately neither picked up the trojan.

    Reckon it could be a false positive? Does that even happen? Or should I try a manual removal? I can hardly find anything about this on the internet - google brings up a load of Chinese results, which is odd seeing as I am in China right now...

  5. #5
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Can't seem to remove a trojan - help appreciated.

    whats the name of the trojan?
    throw new ArgumentException (String, String, Exception)

  6. #6
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.

    Hi TheAnimus.

    Here's the link that microsoft sends:

    http://www.microsoft.com/security/po...2fBancos.gen!A

    It has a fair few names by the looks of things.

  7. #7
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Can't seem to remove a trojan - help appreciated.

    screenshot your contents of:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    throw new ArgumentException (String, String, Exception)

  8. #8
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.


  9. #9
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.

    Sorry - should have expanded that.

    The 3 you can't quite see read:

    Broadcom Wireless Manager UI
    SigmatelSysTrayApp
    Windows Mobile Device Centre

  10. #10
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,027 times in 678 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS

    Re: Can't seem to remove a trojan - help appreciated.


  11. #11
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.

    lol - reckon it's that bad? Atm all it seems to do is cut down my options for online banking in Brazil...

  12. #12
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Can't seem to remove a trojan - help appreciated.

    thing is acording the libs that trojan isn't that advanced. Its not got an entry in the registry to start it, apparently that was the only way it tried to start itself. Might just off been a false posative.

    But sometimes nuking them from space is the only way to be sure.
    throw new ArgumentException (String, String, Exception)

  13. #13
    Senior Member
    Join Date
    Jan 2004
    Location
    Notts UK
    Posts
    766
    Thanks
    11
    Thanked
    55 times in 52 posts

    Re: Can't seem to remove a trojan - help appreciated.

    Fair enough - I've certainly not noticed any weird behaviour - everything seems really slick and there's no weird net activity that I've noticed...

    If I get another positive next time microsoft releases another malicious software removal tool I'll give this a topping - otherwise I'll leave it be.

    Cheers all

  14. #14
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Can't seem to remove a trojan - help appreciated.

    if ur really parinoid give it a run of Mark's RootKit Reliever (sysinternals). If you see anything dodgy, then panic.
    throw new ArgumentException (String, String, Exception)

  15. #15
    jem
    jem is offline
    Registered User
    Join Date
    Oct 2008
    Posts
    0
    Thanks
    15
    Thanked
    1 time in 1 post

    Re: Can't seem to remove a trojan - help appreciated.

    If it was me i would run every free online annti virus i could think off just to be on the safe side.

  16. #16
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Can't seem to remove a trojan - help appreciated.

    but some of the things that masquared as free online anti-virus are just spamware themself?
    throw new ArgumentException (String, String, Exception)

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. How do I remove INF files from my system?
    By poindextermatic in forum Software
    Replies: 5
    Last Post: 16-06-2007, 12:32 AM
  2. Cannot remove viruses
    By SansSouci in forum Help! Quick Relief From Tech Headaches
    Replies: 11
    Last Post: 25-01-2005, 03:44 AM
  3. Removing Axload.E Trojan
    By pickers in forum Software
    Replies: 1
    Last Post: 17-07-2004, 03:09 PM
  4. "Badparty-A" trojan warning
    By Paul Adams in forum Software
    Replies: 3
    Last Post: 17-04-2004, 04:05 PM
  5. Replies: 4
    Last Post: 28-03-2004, 10:33 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •