Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Banker3 trojan??

  • 10-06-2007 5:52pm
    #1
    Banned (with Prison Access) Posts: 2,986 ✭✭✭


    Just this morning when i was browsing the web, i gotta message from my AV program saying virus detected, in fact i got it several times.

    It turn out to be a trojan horse..PSW.Banker3.NRY

    Tried to get some info on it, but could'nt find anything...has anyone come across this pest before??:(

    Thx Phil.


Comments

  • Registered Users, Registered Users 2 Posts: 8,720 ✭✭✭Hal1


    Do a scan using trend micro from their webby and run spybot too if you have it. Those 2 are good at finding trojans / malware etc.


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Do this

    Please download the self-extracting version of HijackThis from here:

    HijackThis_sfx download

    Save HijackThis_sfx to your desktop.

    Double-click the file then click the Unzip button. Then close the Self-Extractor window.

    Using My Computer/Windows Explorer, navigate to C:\Program Files\HijackThis and double click on HijackThis.exe to run it. If you would like to make a shortcut for your Desktop so it's more easily accessable, right click HijackThis.exe and choose Send To > Desktop (create shortcut).

    Please run the extracted HijackThis.exe from now on. Delete any copies of HijackThis.zip that you have saved.

    Open HijackThis and click Do a system scan and save a log file. Copy the entire contents of that log and post it here


  • Closed Accounts Posts: 7,230 ✭✭✭scojones


    If you paste the log into hijackthis.de it will let you know which files are safe to remove.


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    To be honest you shouldn't use hijackthis.de. It's not that good, and misses a lot of bad stuff and other important things that only a person can spot.

    It also doesn't help you delete the files, fix malware in the NT services, or tell you which tools you need to use to clean your PC.

    Also if the user uses hijackthis.de and has HJT in a temp folder, which a lot of people have it in, and if he makes a mistake then he wont be able to restore his backups.

    Sorry to say but hijackthis.de and other programs like it are just a bad idea.


  • Banned (with Prison Access) Posts: 2,986 ✭✭✭philstar


    well i did a scan with AVG and the virus is healed.

    So i just wanted to know have you come across Banker3 before, as i was told it could be a password tracker.


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Have not come across it before, but since it's a password stealer you should change all the passwords for sites from a different pc. Also if you use it for online banking you might want to get in touch with your bank.


  • Closed Accounts Posts: 7,230 ✭✭✭scojones


    To be honest you shouldn't use hijackthis.de. It's not that good, and misses a lot of bad stuff and other important things that only a person can spot.

    It also doesn't help you delete the files, fix malware in the NT services, or tell you which tools you need to use to clean your PC.

    Also if the user uses hijackthis.de and has HJT in a temp folder, which a lot of people have it in, and if he makes a mistake then he wont be able to restore his backups.

    Sorry to say but hijackthis.de and other programs like it are just a bad idea.

    Do you use any sort of tool for interpreting the logs?


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    no tools, just use websites like CastleCops and BleepingComputers for checking a lot of entries.


  • Closed Accounts Posts: 7,230 ✭✭✭scojones


    BleepingComputers is proving to be an invaluable tool. :)


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    I'll post some links if you ever want to try analyse your own log. Although even if you find infections, there's usually a lot more than just fixing them with HijackThis to do.

    The main site I use is
    http://aumha.org/a/hjttutor.php
    That also links you to the main sites when you need to find out about 02/04 entries etc

    This site is considered the "HijackThis Bible"
    http://www.bleepingcomputer.com/tutorials/tutorial42.html

    I have more sites for dealing with infections like WareOut, or Registry tutorials when a reg fix is needed, and more stuff like that. But the two above sites are the best.


  • Advertisement
Advertisement