Nivel de peligro:
9
Tipo: Troyano
Síntomas comunes de infección:
- Se conecta a Internet sin permiso
- Muestra avisos publicitarios
- Los programas normales del sistema fallan inmediatamente
- Conexión lenta a Internet
- Se cae el sistema
- No puedo cambiar mi página de inicio
- Computadora Lenta
Trojan.BankerTrojan.Banker, que está relacionado con Banload y Downloader.Banload, se puede instalar por sí mismo en su PC mediante la vulnerabilidad de un buscador o cualquier otra forma de artimaña. Una vez instalado, el parásito Trojan.Banker monitoreará sus búsquedas e interceptará cuando teclee contraseñas en diferentes páginas web bancarias importantes. El Trojan.Banker abre una gran brecha de seguridad en su computadora y es una amenaza muy peligrosa a la seguridad de sus datos personales y financieros. |
Descargar el escaner para
Trojan.Banker
infecciones
|
Cómo eliminar Trojan.Banker
Archivos asociados con la infección (Trojan.Banker):
winlogon.exe
BrwsPtnr.dll
appconf32.exe
xlr.exe
xln.cpl
xlb.cpl
userviet.exe
Nvsvc32.exe
win32.cpl
sbfiv.exe
hostne.exe
services.exe
ctfmon.exe
krn4.exe
msmsgs.exe
nl6.exe
winnt7.exe
winnt.exe
csrrs2.exe
csrrs1.exe
svchost.exe
spoolsvr32.exe
System32.exe
SerialsWorld[skbhyu].exe
spoolsv.exe
wininit.exe
mydpla.exe
Systema.exe
svhost.exe
Z48B83X1LIB.DLL
WPV501258147400.EXE
winmsne.exe
winnt2.exe
smsni.exe
sms.exe
dll.exe
svchosts.exe
winsex.exe
winnt5.exe
winnt6.exe
winnt3.exe
winnt4.exe
gbieh.dll
iexplorer2.exe
ssmss.exe
systm321.exe
sunwin32.exe
csrss.exe
fc.exe
mac.dll
msbcs.exe
nl.exe
ree1.exe
ree2.exe
WindowsUpdate.scr
iexplore.exe
Explorer.exe
AcroIEHelpe.dll
gbiesrv.exe
netfx20.exe
ntos.exe
load[1].exe
Certificado-4.1.10[1].exe
install_en[1].exe
codecpack.v.1.1.18[1].exe
orkutATupdate.exe
ExAlien.exe
BrwsPtnr.dll
appconf32.exe
xlr.exe
xln.cpl
xlb.cpl
userviet.exe
Nvsvc32.exe
win32.cpl
sbfiv.exe
hostne.exe
services.exe
ctfmon.exe
krn4.exe
msmsgs.exe
nl6.exe
winnt7.exe
winnt.exe
csrrs2.exe
csrrs1.exe
svchost.exe
spoolsvr32.exe
System32.exe
SerialsWorld[skbhyu].exe
spoolsv.exe
wininit.exe
mydpla.exe
Systema.exe
svhost.exe
Z48B83X1LIB.DLL
WPV501258147400.EXE
winmsne.exe
winnt2.exe
smsni.exe
sms.exe
dll.exe
svchosts.exe
winsex.exe
winnt5.exe
winnt6.exe
winnt3.exe
winnt4.exe
gbieh.dll
iexplorer2.exe
ssmss.exe
systm321.exe
sunwin32.exe
csrss.exe
fc.exe
mac.dll
msbcs.exe
nl.exe
ree1.exe
ree2.exe
WindowsUpdate.scr
iexplore.exe
Explorer.exe
AcroIEHelpe.dll
gbiesrv.exe
netfx20.exe
ntos.exe
load[1].exe
Certificado-4.1.10[1].exe
install_en[1].exe
codecpack.v.1.1.18[1].exe
orkutATupdate.exe
ExAlien.exe
Bibliotecas de Vínculos Dinámicos para eliminar (Trojan.Banker):
BrwsPtnr.dll
gbieh.dll
mac.dll
AcroIEHelpe.dll
gbieh.dll
mac.dll
AcroIEHelpe.dll
Procesos para eliminar (Trojan.Banker):
winlogon.exe
SearchSettingsProtection.exe
appconf32.exe
xlr.exe
userviet.exe
Nvsvc32.exe
sbfiv.exe
hostne.exe
services.exe
ctfmon.exe
krn4.exe
msmsgs.exe
nl6.exe
winnt7.exe
winnt.exe
csrrs2.exe
csrrs1.exe
svchost.exe
spoolsvr32.exe
System32.exe
SerialsWorld[skbhyu].exe
spoolsv.exe
wininit.exe
mydpla.exe
Systema.exe
svhost.exe
winmsne.exe
winnt2.exe
smsni.exe
sms.exe
dll.exe
svchosts.exe
winsex.exe
winnt5.exe
winnt6.exe
winnt3.exe
winnt4.exe
iexplorer2.exe
ssmss.exe
systm321.exe
sunwin32.exe
csrss.exe
fc.exe
msbcs.exe
nl.exe
ree1.exe
ree2.exe
iexplore.exe
Explorer.exe
gbiesrv.exe
netfx20.exe
ntos.exe
load[1].exe
Certificado-4.1.10[1].exe
install_en[1].exe
codecpack.v.1.1.18[1].exe
orkutATupdate.exe
ExAlien.exe
ExAlien
SearchSettingsProtection.exe
appconf32.exe
xlr.exe
userviet.exe
Nvsvc32.exe
sbfiv.exe
hostne.exe
services.exe
ctfmon.exe
krn4.exe
msmsgs.exe
nl6.exe
winnt7.exe
winnt.exe
csrrs2.exe
csrrs1.exe
svchost.exe
spoolsvr32.exe
System32.exe
SerialsWorld[skbhyu].exe
spoolsv.exe
wininit.exe
mydpla.exe
Systema.exe
svhost.exe
winmsne.exe
winnt2.exe
smsni.exe
sms.exe
dll.exe
svchosts.exe
winsex.exe
winnt5.exe
winnt6.exe
winnt3.exe
winnt4.exe
iexplorer2.exe
ssmss.exe
systm321.exe
sunwin32.exe
csrss.exe
fc.exe
msbcs.exe
nl.exe
ree1.exe
ree2.exe
iexplore.exe
Explorer.exe
gbiesrv.exe
netfx20.exe
ntos.exe
load[1].exe
Certificado-4.1.10[1].exe
install_en[1].exe
codecpack.v.1.1.18[1].exe
orkutATupdate.exe
ExAlien.exe
ExAlien
Eliminar entradas de registro (Trojan.Banker):
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{B42BF63C-5354-4c5c-A789-66EFEEC5E1B0}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 1260323839
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 2krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 3krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Avast ! Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ csrss
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ddos
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ drivevideo
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ gbiesrv
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ GlobalFlagimglog2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ hostne
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Javs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ krn99
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft security control
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Modulo_Ad_Autorizador
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ msav
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ msbcs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MSMSGS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ netfx20
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PreInstall
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sbfiv
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SerialsWorld
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Service Pack 3
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ smsnisys
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ svchosts
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ svchosts.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System More Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System Update
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Systm32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Technology NT
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winkey
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winmsne
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt3
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt4
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt5
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt6
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt7
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winsex
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinSystem
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ wservices
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xlb
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xln
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xlr
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33161E98-0A6C-4d3c-BD62-3A7D56137F52}
Microsoft\Windows\CurrentVersion\Run\Imparck[1].exe
RUNNING PROGRAM\Explorer.exe
RUNNING PROGRAM\WindowsUpdate.scr
RUNNING PROGRAM\winnt6.exe
{33161E98-0A6C-4d3c-BD62-3A7D56137F52}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{B42BF63C-5354-4c5c-A789-66EFEEC5E1B0}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 1260323839
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 2krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 3krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Avast ! Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ csrss
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ddos
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ drivevideo
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ gbiesrv
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ GlobalFlagimglog2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ hostne
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Javs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ krn
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ krn99
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Messenger
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft security control
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Modulo_Ad_Autorizador
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ msav
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ msbcs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MSMSGS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ netfx20
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PreInstall
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sbfiv
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SerialsWorld
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Service Pack 3
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ smsnisys
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ svchosts
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ svchosts.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System More Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System Update
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Systm32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Technology NT
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winkey
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winmsne
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt3
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt4
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt5
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt6
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winnt7
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winsex
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinSystem
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ wservices
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xlb
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xln
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xlr
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33161E98-0A6C-4d3c-BD62-3A7D56137F52}
Microsoft\Windows\CurrentVersion\Run\Imparck[1].exe
RUNNING PROGRAM\Explorer.exe
RUNNING PROGRAM\WindowsUpdate.scr
RUNNING PROGRAM\winnt6.exe
{33161E98-0A6C-4d3c-BD62-3A7D56137F52}
Comentarios
Descargué un archivo .zip llamado "Shania Twain - You re still the one.zip".
Dentro del zip había un archivo .exe del mismo nombre, que en realidad era el virus Trojan.banker.
Vaya hijos de *****, yo ni he probado, no me da confianza esta web....y ver 0 likes de facebook, si en teoría es para SOLUCIONAR el virus, es raro que 0 likes xD....
***** OFF