Trojan-Downloader.Banload.BXM infection

M

mrs1945

Every day, I run SPYWARE DOCTOR (with latest updates) and each time, Spyware
Doctor detects AND CLEANS the above named infection. It is located in my
Registry as:
HKEY_USERS\S-11-5-21-4168701361-2291903390-2805738209-1006\Software\Microsoft\Windows\CurrentVersion\internet
settings\Post Platform, Embedded Web Browser from: http://bsalsa.com/

Has anyone encountered this infection? If so, can you help me get rid of it
PERMANENTLY?

Any help will be appreciated. Mary
 
D

David H. Lipman

From: "mrs1945" <[email protected]>

| Every day, I run SPYWARE DOCTOR (with latest updates) and each time, Spyware
| Doctor detects AND CLEANS the above named infection. It is located in my
| Registry as:
| HKEY_USERS\S-11-5-21-4168701361-2291903390-2805738209-1006\Software\Microsoft\Windows\Curr
| entVersion\internet settings\Post Platform, Embedded Web Browser from: http://bsalsa.com/
|
| Has anyone encountered this infection? If so, can you help me get rid of it
| PERMANENTLY?
|
| Any help will be appreciated. Mary


Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

Create a HJT log file and post it in one of the below locations...

{ Please - Do NOT post the HJT Log here ! }

Forums where you can get expert advice for HiJack This! (HJT) logs.

NOTE: Registration is REQUIRED in any of the below before posting a log

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html

Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.malwarebytes.org/forums/index.php?showforum=7
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13
 
N

nass

mrs1945 said:
Every day, I run SPYWARE DOCTOR (with latest updates) and each time, Spyware
Doctor detects AND CLEANS the above named infection. It is located in my
Registry as:
HKEY_USERS\S-11-5-21-4168701361-2291903390-2805738209-1006\Software\Microsoft\Windows\CurrentVersion\internet
settings\Post Platform, Embedded Web Browser from: http://bsalsa.com/

Has anyone encountered this infection? If so, can you help me get rid of it
PERMANENTLY?

Any help will be appreciated. Mary

This an application been installed by you or somebody else to Enhance the IE
browser and connection to the Internet either by your ISP or through a
third-party software you trusted?.
Open the Control panel then click on Add/Remove programs and look for the
Bsala Embedded web browser form and unistall it.

Go through these Cleaning steps:
1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit .
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html
RootkitRevealer v1.71
By Bryce Cogswell and Mark Russinovich
http://www.microsoft.com/technet/sysinternals/Security/RootkitRevealer.mspx

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (off-line scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (off-line scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk clean-up on your drive

Download the Hijackthis and send the report to one of
many
forums for analysis and troubleshooting:
When all else fails, HijackThis v2.0.2
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php) is
the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. Post
your log to:
http://www.spywareinfo.com/~merijn/downloads.html
http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7
http://www.bleepingcomputer.com/tutorials/tutorial42.html
http://www.bleepingcomputer.com/forums/
Or other appropriate
forums for expert analysis, not here.
Can you please send me a copy at (e-mail address removed) , remove
the obvious to email me.
Let us know your progress.
nass
 
S

smot

"This an application been installed by you or somebody else to Enhance
the IE
browser and connection to the Internet either by your ISP or through
a
third-party software you trusted?.
Open the Control panel then click on Add/Remove programs and look for
the
Bsala Embedded web browser form and unistall it. "

Hello

The Embedded Webbrowser Control is an enhanced Microsoft ActiveX
control which can be embedded in Delphi applications.
The Control is changing the UserAgent in the registry.

It cannot be removed through "Add/Remove programs"

Thomas
 
D

David H. Lipman

From: "smot" <[email protected]>

| "This an application been installed by you or somebody else to Enhance
| the IE
| browser and connection to the Internet either by your ISP or through
| a
| third-party software you trusted?.
| Open the Control panel then click on Add/Remove programs and look for
| the
| Bsala Embedded web browser form and unistall it. "
|
| Hello
|
| The Embedded Webbrowser Control is an enhanced Microsoft ActiveX
| control which can be embedded in Delphi applications.
| The Control is changing the UserAgent in the registry.
|
| It cannot be removed through "Add/Remove programs"
|
| Thomas

Huh ?
I can't understand WHAT you are trying to state.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top