Author Topic: JS:Banker-D  (Read 11172 times)

0 Members and 1 Guest are viewing this topic.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: JS:Banker-D
« Reply #15 on: February 06, 2011, 12:40:25 AM »
Did it!
:- )

It is still there in the post where you quoted essexboy's fix, in Reply #10 (http://forum.avast.com/index.php?topic=70760.msg593483#msg593483). Although the quoted text is his, it is in your post so you can also modify that and change the http to hxxp.

Or are you talking about the cleanup of OTL ?
If so you also have to modify your post to prevent accidental exposure to a malicious site.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

pablomaz

  • Guest
Re: JS:Banker-D
« Reply #16 on: February 07, 2011, 12:52:20 PM »
Did it!
:- )

It is still there in the post where you quoted essexboy's fix, in Reply #10 (http://forum.avast.com/index.php?topic=70760.msg593483#msg593483). Although the quoted text is his, it is in your post so you can also modify that and change the http to hxxp.

Or are you talking about the cleanup of OTL ?
If so you also have to modify your post to prevent accidental exposure to a malicious site.

I'm sorry David, I missed that one... I think it's ok now.
Thank you, my friends!

pablomaz

  • Guest
Re: JS:Banker-D
« Reply #17 on: February 07, 2011, 12:54:12 PM »
Quote
Internet Settings: "AutoConfigURL" = hxxp://www.windows72.net/0xf04.pac
It was autoconfiguring all urls to be routed via this site.  Unfortunately no malware removal tools check this area as there are too many variables

Run OTL and hit the cleanup button now  ;D

Oh, I get it... Very clever.  ;D
Thanks, man!

SlaineMacRoth

  • Guest
Re: JS:Banker-D
« Reply #18 on: January 26, 2012, 12:22:48 AM »
I believe I've found the answer to this one. Its a registry setting located at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
There should be a key named AutoConfigURL which points to a text file located on your PC. Mine was named KB_Beast.txt (Beast being the name of my PC). This text file had loads of banking sites, hotmail, Gmail, Paypal sites listed. I deleted the value for the AutoConfigRL key and havent had any warnings since. On the plus side it seems Avast has been blocking this script from running. I hope this helps in your case as well.

Regards

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: JS:Banker-D
« Reply #19 on: January 26, 2012, 12:25:48 AM »
@SlaineMacRoth    did you check the date on this topic ?

last post was feb 2011   ;)