Remove Trojan-BNK.Win32.Keylogger.gen
. Description and removal instructions
Title: Trojan-BNK.Win32.Keylogger.gen |
Also known as: Trojan-BNK.Win32.Keylogger.gen | |
Type: Adware |
Severity scale: (31 / 100) |
Trojan-BNK.Win32.Keylogger.gen is a dangerous infection that spreads through XP Internet Security 2010 rogue anti-spyware program. It is not a real virus and it appears only if the system is infected with XP Internet Security 2010.
Once computer is infected with this fake application and you try to browse some Internet website, XP Internet Security 2010 keeps displaying fake notifications claiming that your system is infected with Trojan-BNK.Win32.Keylogger.gen. The warning states that your private data (passwords, credit card details, etc.) might be stolen. However, this warning is a total lie. Trojan-BNK.Win32.Keylogger.gen was only designed to scare people into thinking it’s a dangerous infection. Such parasite doesn’t even exist on your computer and it is displayed just because you are infected with XP Internet Security 2010. This is the only application that must be removed.
Once you get notifications that you are infected with Trojan-BNK.Win32.Keylogger.gen, concentrate on removing XP Internet Security 2010 application.
Discuss Trojan-BNK.Win32.Keylogger.gen in
spyware removal forum
Related files: WRblt8464P, av.exe
Trojan-BNK.Win32.Keylogger.gen properties:
• Connects itself to the internet
• Stays resident in background
Trojan-BNK.Win32.Keylogger.gen snapshot:
Automatic Trojan-BNK.Win32.Keylogger.gen removal:
Trojan-BNK.Win32.Keylogger.gen manual removal:
Delete registry values:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1?
how to remove registry entries
Delete files:
av.exe WRblt8464P
how to remove harmful files
Delete directories:
%Documents and Settings%\[UserName]\Application Data\