how do I remove a trojan called trojan-spy.banker.chc?

Posted on 2007-10-03
Last Modified: 2013-12-09
I have one PC on a microsoft network that has a trojan virus. Symantec antivirus 10.1.5 does not find it but PC tools spyware doctor finds it. It appears to remove it when it's disconnected from the network but as soon as I plug in the T/P cable it reappears. The only info I can find on the internet calls it "Trojan-Spy.Banker.CHC". It says that it was created in Brazil and is also known as Troj/Bancos-BBU. I really need info on how to remove this trojan.
Question by:mkaczowski
    LVL 3

    Expert Comment

    Go into safe mode, and then run pctools spyware doctor. Once detected, remove it and restart your computer in normal mode and check to see if the problem has been solved.

    You can go into safe mode by pressing F5 during boot up and selecting safe mode.
    LVL 4

    Expert Comment


    Connect with, it's free scan from McAfee (in Spanish, but its the same result) CLICK ON "Analizar ahora" (Analize now), accept download from and follow instrucctions for removal.
    remember: don't restore system to previous instant, do not use tape or cd or dvd backups for recover info without scan it.

    Good luck
    LVL 23

    Expert Comment

    Bitdefender should get rid of it:

    Free fully fuctional scan here:

    If you still have problems, a Hijack This log would be helpful:

    Good luck!!!
    LVL 65

    Accepted Solution

    boot into safemode with should't load under safemode and then run the online virus scanner to get it rmeoved

    Author Comment

    So far running SpDoctor in safe mode with system restore disabled failed to remove the trojan.
    Once you reboot in normal mode with internet access, it recreates a startt.job and a start.bat file in Windows and it reinfects the system.

    The McAfee in spanish found two other cases of Banker.chc and said that it removed them but once again on bootup it became reinfected.

    I will try Bitdefender and trendmicro next.

    Does the bitdefender have to run in safe mode or can it run in normal mode with the network attached?

    Super desperate,
    LVL 23

    Expert Comment

    Yes, Bitdefender will run in Safe Mode with Networking

    Another tool to consider in getting rid of this thing is Combofix:

    Double click combofix.exe & follow the prompts.

    LVL 1

    Expert Comment

    If you know where all the files live related to this trojan, remove them manually. Check MSCONFIG and remove the call that reinfects the system.

    I usually use Process Explorer to get the right information.
    LVL 47

    Expert Comment

    As already suggested,
    Can you run Hijackthis and show us the log please?
    Open Hijackthis, click "Do a system scan and save a logfile" please don't fix anything yet.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Join & Write a Comment

    Suggested Solutions

    This article summarizes using a simple matrix to map the different type of phishing attempts and its targeted victims. It also run through many scam scheme scenario with "real" phished emails. There are safeguards highlighted to stay vigilance and h…
    Article by: btan
    The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    how to add IIS SMTP to handle application/Scanner relays into office 365.

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now