Author Topic: BankerFox.A and Nugel Trojan-Dropper  (Read 10954 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: BankerFox.A and Nugel Trojan-Dropper
« Reply #15 on: June 21, 2010, 10:07:15 PM »
Ok there is more than one way to skin a cat

Do you have access to another computer with a  cd burner ?  You should be able to access the internet with the Reatogo system

Please print these instruction out so that you know what you are doing

File details OTLPENet.exe
Bytes=126,850,486
MB=120.9
MD5=8A7C5BA1C92552ADDCC5E468D0AA069A




  • Download OTLPENet.exe to your desktop
  • Ensure that you have a blank CD in the drive
  • Double click OTLPENet.exe and this will then open imgburn  to burn the file to CD

  • Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads  :) 
  • Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start.
  • Drag and drop this attached scan.txt into the Custom scans and fixes box
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system.
  • Right click the file and select send to : select the USB drive. 
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: BankerFox.A and Nugel Trojan-Dropper
« Reply #16 on: June 22, 2010, 02:51:36 AM »
I contacted Avast Tech Support 4 hours ago and have a ticket number.  I have yet to receive a reply.
Well... give them some time :)

Which is your operational system?
There are some solutions posted here: http://www.softwaretipsandtricks.com/forum/windows-xp/13705-missing-add-remove-programs-option.html
Also http://www.kellys-korner-xp.com/xp_tweaks.htm and http://www.easydesksoftware.com/regtrick.htm
The best things in life are free.

Kimmon

  • Guest
Re: BankerFox.A and Nugel Trojan-Dropper
« Reply #17 on: June 22, 2010, 04:13:41 AM »
Essexboy & Tech

Thanks for your help.  I had to bail out earlier to take care of a business emergency. 

Anyway, a colleague of mine who also is a webmaster for several sites has agreed to fix this for me. His skills far exceed mine in this area. Also, his menu of remedies is very similar to yours and he is very familiar with the BankerFox.A problem since he has resolved this for many people.

Thanks again.


MTW

  • Guest
Re: BankerFox.A and Nugel Trojan-Dropper
« Reply #18 on: June 22, 2010, 04:47:15 AM »
Good luck
« Last Edit: June 22, 2010, 04:50:59 AM by MTW »

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: BankerFox.A and Nugel Trojan-Dropper
« Reply #19 on: June 22, 2010, 04:54:37 AM »
Start computer in Safe Mode (pressing F8 key) and set an avast boot-time scan (if yoy havent tried this already). Restart computer and let scan run. Move to chest any files brought up in scan.

Then follow directions from Essexboy and see how plan will run

edit - sorry didn't see second page. Good luck folks.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.