We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
TrojanSpy:Win32/Banker.JV.dll
Detected by Microsoft Defender Antivirus
Aliases: PWS-Banker.j (McAfee) PWSteal.Trojan (Symantec) Troj/BankAsh-A (Sophos) Win32/PSW.Bancos.163840!Trojan (CA)
Summary
TrojanSpy:Win32/Banker.JV drops TrojanSpy:Win32/Banker.JV.dll and registers it as an Internet Explorer browser helper object (BHO). The .dll file monitors user browsing activity and captures logon information at certain online banking Web sites. It then sends this information to a remote server.
To recover manually from TrojanSpy:Win32/Banker.JV.dll, follow these steps:
- Disconnect from the Internet.
- Delete the .dll file.
- Restart your computer.
- Take steps to prevent re-infection.
Disconnect from the Internet
To help ensure that your computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.
Delete the .dll file
To delete the .dll file
- Click Start, and click Run.
- In the Open field, type <system folder>, for example, C:\Windows\System32
- Click OK.
- Click Name to sort files by name.
- If the file ash.dll is in the list, delete it.
- On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
- Click Yes to confirm the deletion.
Restart your computer
To restart your computer
- On the Start menu, click Shut Down.
- Select Restart from the drop-down list and click OK.
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.