📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Trojan-BNK.Win32.Keylogger.gen removal

Options
I have just used malawarebytes to remove "Trojan-K.Win32.Keylogger.gen"
which it seemed to do successfully.

However on rebooting the computer every file (.exe program) that i try to open, asks me to select the program from the list or use the internet to search for the the extension!!

I think when i removed the trojan, that it did something with the registry so im guessing that could be the problem.

I havnt done anything else because I know ill proberbly mess things up!

Can anyone advise??
Nice to save.
«1

Comments

  • debitcardmayhem
    debitcardmayhem Posts: 12,763 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    lesley2004 wrote: »
    I have just used malawarebytes to remove "Trojan-K.Win32.Keylogger.gen"
    which it seemed to do successfully.

    Can anyone advise??
    Post the malwarebytes log would help + a HijackThis log too..
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • lesley2004
    lesley2004 Posts: 296 Forumite
    Thanks so far I have merged http://www.users.on.net/~russ/exe_fix_w7.reg

    But that has not worked.


    The malaware log appears to be missing I cannot locate it

    System restore is turned off and I cant get it back on

    The shift and right click has allowed me to run AVG but it wont let me open malawarebytes an error comes up

    I will have to call it a night for now otherwise I will never get up for work!!. Tomorrow I will download hijack this and post a log

    Thanks so much for your help so far I will not get back to this until tomorrow night now.
    Nice to save.
  • lesley2004
    lesley2004 Posts: 296 Forumite
    Hijack this downloads but will not run-comes up with runtime error 481.

    Definatley off to bed now hope you will be able to help tomorrow

    Thanks
    Nice to save.
  • lesley2004
    lesley2004 Posts: 296 Forumite
    edited 13 June 2011 at 8:31PM
    Hi again

    Still having problems. IE works. AVG opens but wont run.

    downloaded malawarebytes/hijackthis/surfright/combofix without difficulty but cannot open comes up with runtime error/error launching installer.

    Think I may just return to factory settings and as it is just a netbook I could save any pics etc as I am able to access them. However not sure how to do system restore on windows 7

    Any advice would be appreciated

    Lesley
    Nice to save.
  • lesley2004
    lesley2004 Posts: 296 Forumite
    edited 13 June 2011 at 8:49PM
    I tried shift and rt click which opened avg but it would not work
    I did not know how to rename files
    Did not understanf the bit about system restore?

    Is it easy to do the above?
    Nice to save.
  • lesley2004
    lesley2004 Posts: 296 Forumite
    ok i think you are right

    Many thanks for your help.
    Nice to save.
  • Bogtrotter
    Bogtrotter Posts: 1,031 Forumite
    The runtime error 481 seems to be generally associated with invalid image files???

    I'm assuming you cannot run regedit.exe by clicking Start and typing regedit into search and selecting regedit from the search result.

    However try start regedit by

    Press Ctrl-Alt-Delete and start Task Manager
    Hold in Ctrl and select "New Task (Run)" from the file menu... this should bring up a black window with white text commandline.
    Type regedit into the commandline and press enter

    Does that work?
  • lesley2004
    lesley2004 Posts: 296 Forumite
    Yes that does work..............but what I am I supposed to do now?
    Nice to save.
  • Bogtrotter
    Bogtrotter Posts: 1,031 Forumite
    edited 14 June 2011 at 9:54AM
    Ok if you can run regedit by the second method but not the first it suggests the association for the .exe is broken.

    Viruses or malware can alter the registry to automatically run the virus program each time you execute any program.

    First start regedit and backup registry.

    Then in regedit navigate to HKEY_CLASSES_ROOT\exefile\shell\open\command (this is the key commonly altered) the default key should be "%1" %* anything else remove or alter.

    Reboot and check if you can run programs now.
  • lesley2004
    lesley2004 Posts: 296 Forumite
    not wanting to sound too stupid how do i back up registry?

    when navigating to
    H-KEY-CLASSES_ROOT\exefile\shell\open\command

    when i open shell there are 2 files

    one is called open with a default key that has no data set but there is no command key

    the other is runas which when I open reveals command
    then there is default key which is "%1" %*
    and isolated.com key which also says "%1" %*

    Does that sound right?
    Nice to save.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599.1K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.