<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Trojan-BNK.Win32.Keylogger.gen</title>
	<atom:link href="http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen/feed" rel="self" type="application/rss+xml" />
	<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen</link>
	<description></description>
	<lastBuildDate>Thu, 09 Feb 2012 13:37:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Kyle</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-102888</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Sun, 15 Jan 2012 14:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-102888</guid>
		<description>Just a lil heads up, 
trojan killer can fail since it blocks programmes, and when you go into safe mode it requires internet and activation to actually remove the malware. so it&#039;s not much of help when you most need it. But through playing in safemode, without network connection, there is something you can do that works effectively. first close the pop-ups of the remaining trash, they will only pop up like once. then launch events by ctrl-alt-del, start new task &gt; browse &gt; in the side window of search or in help type configuration panel - system - ... - system restore. then you can finally activate it. pick a week or so behind and it will switch before this trash popped up. thats if the trojan blocked all applications including system restore from the normal mode.</description>
		<content:encoded><![CDATA[<p>Just a lil heads up,<br />
trojan killer can fail since it blocks programmes, and when you go into safe mode it requires internet and activation to actually remove the malware. so it&#8217;s not much of help when you most need it. But through playing in safemode, without network connection, there is something you can do that works effectively. first close the pop-ups of the remaining trash, they will only pop up like once. then launch events by ctrl-alt-del, start new task &gt; browse &gt; in the side window of search or in help type configuration panel &#8211; system &#8211; &#8230; &#8211; system restore. then you can finally activate it. pick a week or so behind and it will switch before this trash popped up. thats if the trojan blocked all applications including system restore from the normal mode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AH</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-102857</link>
		<dc:creator>AH</dc:creator>
		<pubDate>Sun, 15 Jan 2012 12:59:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-102857</guid>
		<description>Thank you Mike!   We are running Vista and everything working fine now!   Saved us a lot of time and money getting fixed.   Thank you so much...</description>
		<content:encoded><![CDATA[<p>Thank you Mike!   We are running Vista and everything working fine now!   Saved us a lot of time and money getting fixed.   Thank you so much&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-99436</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Thu, 05 Jan 2012 19:48:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-99436</guid>
		<description>&lt;a href=&quot;#comment-38337&quot; rel=&quot;nofollow&quot;&gt;@admin &lt;/a&gt; 
I purchased Kaspersky to keep three computers clean.
Not only does it fail miserably, three scans and more wasted time have convinced me never to renew with them again.
They do not even mention or allow a search for this virus on their website.
There goes your credibility Kaspersky, you get an &quot;F&quot; for customer service.</description>
		<content:encoded><![CDATA[<p><a href="#comment-38337" rel="nofollow">@admin </a><br />
I purchased Kaspersky to keep three computers clean.<br />
Not only does it fail miserably, three scans and more wasted time have convinced me never to renew with them again.<br />
They do not even mention or allow a search for this virus on their website.<br />
There goes your credibility Kaspersky, you get an &#8220;F&#8221; for customer service.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RLM</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98657</link>
		<dc:creator>RLM</dc:creator>
		<pubDate>Wed, 04 Jan 2012 01:45:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98657</guid>
		<description>But how do you go to the next entry without hitting the enter key? (see codes at top)
&lt;a href=&quot;#comment-13286&quot; rel=&quot;nofollow&quot;&gt;@Gianpietro Signorini&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>But how do you go to the next entry without hitting the enter key? (see codes at top)<br />
<a href="#comment-13286" rel="nofollow">@Gianpietro Signorini</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98575</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 03 Jan 2012 21:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98575</guid>
		<description>Franchise
There are 2 separate issues in your case. 
1. Browser hijacking, read our walkthrough here : http://www.2-viruses.com/how-to-fix-google-results-hijacker-google-redirect-virus-problem
2. Exe execution issues - you will need to fix .exe file execution in your registry, either with regedit, through control panel restoring default associations or importing correct registry</description>
		<content:encoded><![CDATA[<p>Franchise<br />
There are 2 separate issues in your case.<br />
1. Browser hijacking, read our walkthrough here : <a href="http://www.2-viruses.com/how-to-fix-google-results-hijacker-google-redirect-virus-problem" rel="nofollow">http://www.2-viruses.com/how-to-fix-google-results-hijacker-google-redirect-virus-problem</a><br />
2. Exe execution issues &#8211; you will need to fix .exe file execution in your registry, either with regedit, through control panel restoring default associations or importing correct registry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Franchise</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98508</link>
		<dc:creator>Franchise</dc:creator>
		<pubDate>Tue, 03 Jan 2012 17:55:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-98508</guid>
		<description>Restoring my laptop to a prior date worked.  Now I am thinking I need to run / install anti-virus protection to basically scrub everything just to be safe.  However, I am not able to run downloads from Microsoft security Essentials or Avast (the two anti-virus programs I was considering).  I am suspcious that my problems downlading Microsoft essentials or Avast is because of a more general problem (a new problem) associated with exe files that did not exist before this virus.  Two questions 1.) is there a free anti-virus program anyone would recommend that would be good after encountering this virus?  2.) is my suspicion of exe file problems common in the aftermath of this virus or am I just being paranoid?</description>
		<content:encoded><![CDATA[<p>Restoring my laptop to a prior date worked.  Now I am thinking I need to run / install anti-virus protection to basically scrub everything just to be safe.  However, I am not able to run downloads from Microsoft security Essentials or Avast (the two anti-virus programs I was considering).  I am suspcious that my problems downlading Microsoft essentials or Avast is because of a more general problem (a new problem) associated with exe files that did not exist before this virus.  Two questions 1.) is there a free anti-virus program anyone would recommend that would be good after encountering this virus?  2.) is my suspicion of exe file problems common in the aftermath of this virus or am I just being paranoid?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffrey</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97726</link>
		<dc:creator>Jeffrey</dc:creator>
		<pubDate>Sun, 01 Jan 2012 23:27:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97726</guid>
		<description>Thanks for all the help Mike. I almost paid $200 to have the virus removed by someone and would have taken longer. Thanks! You are a lifesaver!</description>
		<content:encoded><![CDATA[<p>Thanks for all the help Mike. I almost paid $200 to have the virus removed by someone and would have taken longer. Thanks! You are a lifesaver!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yee Ling</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97455</link>
		<dc:creator>Yee Ling</dc:creator>
		<pubDate>Sun, 01 Jan 2012 02:28:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97455</guid>
		<description>Okay, I just found out that keying-in the serial numbers didn&#039;t really remove the virus. To remove the virus totally, you need to follow these 3 steps:

1) Download malwarebytes 
2) Go to safe mode (Keep pressing the F8 button before windows starts up)
3) When in safe mode, right click on the malwarebytes install file and choose &quot;run as the administrator&quot; and install. You wont be able to update it because of the virus but perform a quick scan anyway. Delete the virus after that and it&#039;s all done.

* I was using AVG free antivirus before all these. Somehow, after keying in the serial numbers, although my internet explorer and google chrome are finally working, my AVG cannot start up at all. The &quot;Win 7 Antivirus 2012&quot; program is still there, remains as a hidden icon. There are some suspicious programs running at the same time too (eg. 321.exe and AVG tray). After performed a quick scan using Malwarebytes, I&#039;m glad that the virus is totally removed now as I can finally opened the AVG file on my desktop again. 

Good luck!</description>
		<content:encoded><![CDATA[<p>Okay, I just found out that keying-in the serial numbers didn&#8217;t really remove the virus. To remove the virus totally, you need to follow these 3 steps:</p>
<p>1) Download malwarebytes<br />
2) Go to safe mode (Keep pressing the F8 button before windows starts up)<br />
3) When in safe mode, right click on the malwarebytes install file and choose &#8220;run as the administrator&#8221; and install. You wont be able to update it because of the virus but perform a quick scan anyway. Delete the virus after that and it&#8217;s all done.</p>
<p>* I was using AVG free antivirus before all these. Somehow, after keying in the serial numbers, although my internet explorer and google chrome are finally working, my AVG cannot start up at all. The &#8220;Win 7 Antivirus 2012&#8243; program is still there, remains as a hidden icon. There are some suspicious programs running at the same time too (eg. 321.exe and AVG tray). After performed a quick scan using Malwarebytes, I&#8217;m glad that the virus is totally removed now as I can finally opened the AVG file on my desktop again. </p>
<p>Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97144</link>
		<dc:creator>Shawn</dc:creator>
		<pubDate>Sat, 31 Dec 2011 06:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97144</guid>
		<description>Thanks for your Help</description>
		<content:encoded><![CDATA[<p>Thanks for your Help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shawn</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97143</link>
		<dc:creator>Shawn</dc:creator>
		<pubDate>Sat, 31 Dec 2011 06:01:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-97143</guid>
		<description>My daughter&#039;s NEW laptop is infected.  I tried to install Trend Micro which I have used for years, but cannot get on the internet. I read #54 and tried those steps but cannot get past &quot;System Restore&quot; to enter date.  The Win 7 Security 2012 Firewall alert keeps popping up.</description>
		<content:encoded><![CDATA[<p>My daughter&#8217;s NEW laptop is infected.  I tried to install Trend Micro which I have used for years, but cannot get on the internet. I read #54 and tried those steps but cannot get past &#8220;System Restore&#8221; to enter date.  The Win 7 Security 2012 Firewall alert keeps popping up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-95991</link>
		<dc:creator>Jeremy</dc:creator>
		<pubDate>Thu, 29 Dec 2011 03:26:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-95991</guid>
		<description>see post #54 &lt;a href=&quot;#comment-34594&quot; rel=&quot;nofollow&quot;&gt;@Brandi&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>see post #54 <a href="#comment-34594" rel="nofollow">@Brandi</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-95989</link>
		<dc:creator>Jeremy</dc:creator>
		<pubDate>Thu, 29 Dec 2011 03:25:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-95989</guid>
		<description>control panel &gt; system and maintenance &gt; Back up and restore &gt; repair windows using system restore.   Set date of restore back a few days before you first noticed the problem.     Easiest fix available!   Works on Vista.  Don&#039;t know about XP.  Get your computer manual and look up system restore if you want a better explanation.     I could not get restore to work in safe mode because the &quot;virus&quot; was blocking it, but it worked in normal operating mode.   Oh ya.....disconnect from any network you are on.</description>
		<content:encoded><![CDATA[<p>control panel &gt; system and maintenance &gt; Back up and restore &gt; repair windows using system restore.   Set date of restore back a few days before you first noticed the problem.     Easiest fix available!   Works on Vista.  Don&#8217;t know about XP.  Get your computer manual and look up system restore if you want a better explanation.     I could not get restore to work in safe mode because the &#8220;virus&#8221; was blocking it, but it worked in normal operating mode.   Oh ya&#8230;..disconnect from any network you are on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DarkPhoenix</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-93184</link>
		<dc:creator>DarkPhoenix</dc:creator>
		<pubDate>Fri, 23 Dec 2011 00:34:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-93184</guid>
		<description>Thank you for this post... It was a great help for Windows 7 with nasty critter!</description>
		<content:encoded><![CDATA[<p>Thank you for this post&#8230; It was a great help for Windows 7 with nasty critter!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Madashell</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-91074</link>
		<dc:creator>Madashell</dc:creator>
		<pubDate>Mon, 19 Dec 2011 16:56:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-91074</guid>
		<description>I got this virus/trojan on Saturday. I think I had it for one or two days longer because my computer started getting these restart message for important updates and error messages on the same days. I have tried everything. This bastard has completely taken over my laptop and any antivirus software that I install has been taken over. Even the norton that has been on my laptop and updated to the newest version has been infected. It has infected the Adobe media player and everything else. I can&#039;t do any thing becausE my entire computer and settings have been changed. I don&#039;t know what to do. None of these fixes work.</description>
		<content:encoded><![CDATA[<p>I got this virus/trojan on Saturday. I think I had it for one or two days longer because my computer started getting these restart message for important updates and error messages on the same days. I have tried everything. This bastard has completely taken over my laptop and any antivirus software that I install has been taken over. Even the norton that has been on my laptop and updated to the newest version has been infected. It has infected the Adobe media player and everything else. I can&#8217;t do any thing becausE my entire computer and settings have been changed. I don&#8217;t know what to do. None of these fixes work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guy spennato</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-87623</link>
		<dc:creator>guy spennato</dc:creator>
		<pubDate>Mon, 12 Dec 2011 15:58:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-87623</guid>
		<description>my computer is infected</description>
		<content:encoded><![CDATA[<p>my computer is infected</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-86804</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sat, 10 Dec 2011 18:38:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-86804</guid>
		<description>Mike, great post.  I&#039;m running Win7 SP1. As soon as I starting seeing the WindowsSecurity Center popups, I removed the machine from the network (to prevent talkbacks and/or furthur spread).  The popup request from &#039;Windows Security Center&quot; requesting a purchase of a product that our admin group has licensed, caused me suspicion... 

I booted into safe mode:

1) Used regedit to figure out the usurped startup command (I choose firefox only because it was an application that I knew had been mucked with) - HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “\Users\root\AppData\local\vfu.exe&quot; -a “firefox.exe”.

2) Renamed the file (in /Users/root/AppData/Local) to xxx.xxx, couldn&#039;t delete at this point.

3) Ran regedit and searched for any/all ocurrences of vfu.exe, changed those back to &quot;%1&quot; %*.

4) Rebooted into safe mode again.

5) Removed /Users/root/AppData/Local/xxx.xxx.


6) Now doing full scan with SEVERAL tools, before plugging back into ANY network.</description>
		<content:encoded><![CDATA[<p>Mike, great post.  I&#8217;m running Win7 SP1. As soon as I starting seeing the WindowsSecurity Center popups, I removed the machine from the network (to prevent talkbacks and/or furthur spread).  The popup request from &#8216;Windows Security Center&#8221; requesting a purchase of a product that our admin group has licensed, caused me suspicion&#8230; </p>
<p>I booted into safe mode:</p>
<p>1) Used regedit to figure out the usurped startup command (I choose firefox only because it was an application that I knew had been mucked with) &#8211; HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “\Users\root\AppData\local\vfu.exe&#8221; -a “firefox.exe”.</p>
<p>2) Renamed the file (in /Users/root/AppData/Local) to xxx.xxx, couldn&#8217;t delete at this point.</p>
<p>3) Ran regedit and searched for any/all ocurrences of vfu.exe, changed those back to &#8220;%1&#8243; %*.</p>
<p>4) Rebooted into safe mode again.</p>
<p>5) Removed /Users/root/AppData/Local/xxx.xxx.</p>
<p>6) Now doing full scan with SEVERAL tools, before plugging back into ANY network.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ami</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-85870</link>
		<dc:creator>Ami</dc:creator>
		<pubDate>Thu, 08 Dec 2011 17:45:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-85870</guid>
		<description>I did system restore to a previous date of three days, and everything seems to be going okay now.  What a pain!</description>
		<content:encoded><![CDATA[<p>I did system restore to a previous date of three days, and everything seems to be going okay now.  What a pain!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sid</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-83815</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Sun, 04 Dec 2011 20:11:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-83815</guid>
		<description>mike please helpe me get this of my pc trojan e mail me andexplane    &lt;a href=&quot;#comment-38266&quot; rel=&quot;nofollow&quot;&gt;@Mike &lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>mike please helpe me get this of my pc trojan e mail me andexplane    <a href="#comment-38266" rel="nofollow">@Mike </a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-83494</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Sun, 04 Dec 2011 00:27:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-83494</guid>
		<description>This worked great for me as well.  I&#039;m on Windows 7 so it was a bit differently to get to the system restore (windows wanted to find and fix the problem itself but couldn&#039;t) which I couldn&#039;t repeat here as had to turn off and reboot a few times and have it fail doing a system &quot;recovery&quot; before it came to the option of me being able to do the system restore.  

As a side, I got this a couple of years ago and did the whole registery edit approach.  That worked but took a lot longer.</description>
		<content:encoded><![CDATA[<p>This worked great for me as well.  I&#8217;m on Windows 7 so it was a bit differently to get to the system restore (windows wanted to find and fix the problem itself but couldn&#8217;t) which I couldn&#8217;t repeat here as had to turn off and reboot a few times and have it fail doing a system &#8220;recovery&#8221; before it came to the option of me being able to do the system restore.  </p>
<p>As a side, I got this a couple of years ago and did the whole registery edit approach.  That worked but took a lot longer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-82983</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 02 Dec 2011 21:57:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.2-viruses.com/remove-trojan-bnk-win32-keylogger-gen#comment-82983</guid>
		<description>Lisa : use usb key. Also, disable proxy in your browser.</description>
		<content:encoded><![CDATA[<p>Lisa : use usb key. Also, disable proxy in your browser.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

