Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Bancos Virus

Posted on 2008-11-04
16
Medium Priority
?
1,099 Views
Last Modified: 2011-10-19
Dear Experts,

My laptop has become infected with Bancos virus. Does this forum have any solution for the removal of the virus.

What are the possible alternatives.

Thank you,
0
Comment
Question by:Excellearner
  • 7
  • 5
  • 3
  • +1
16 Comments
 
LVL 3

Expert Comment

by:tdor
ID: 22880185
Hi

 I would recommend that you use the on line Anti-virus scan from Kaspersky
http://www.kaspersky.com/virusscanner

Regards,
Tdor
0
 
LVL 27

Expert Comment

by:David-Howard
ID: 22880506
I would also recommend downloading and updating malwarebytes.
You can get it free from www.malwarebytes.org
Once updated, reboot into Safe Mode (F8 at startup) and run a scan.
You should do this with your current antivirus product as well.
David
0
 

Author Comment

by:Excellearner
ID: 22881506
David/tdor,

Does your suggestions by runing the urls clean the virus from laptop orjust identify the virus.

Do i need take a back and how do i do it.

My laptop is acer aspire 5720.

Thank you
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 
LVL 3

Expert Comment

by:tdor
ID: 22881662
Hi,

I it cannot remove the virus try some a sollution from another AV
http://wiki.castlecops.com/Malware_Removal:_Online_Anti-Virus_Scans

This virus is pretty old so it should be removed by any AV you're using (suggest you do a full scan)

tdor
0
 

Author Comment

by:Excellearner
ID: 22881787
tdor,

thank you for the email and sorry to come back to you on the same questuion.

Does the software in the above url remove the virus or just detect.

Which av sotware do you recommend for house hold purpose. I visit type of websites. SO i need a comprehensive solution.

Thank you
0
 
LVL 3

Expert Comment

by:tdor
ID: 22881832
Hi,

Checked and on Kaspersky's site it says that it just detects but do not remove
If your AV do not work you might want to try this http://free.avg.com/. I tryied and it's prety ok as a home AV


tdor
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 22881998
If Malwarebytes or Kaspersky free trial or other scanners already mentioned fails to remove it, then try Combofix (we need to see the logfile afterwards so we can make a script to remove any files not removed in the first run)

Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
 
0
 

Author Comment

by:Excellearner
ID: 22913082
rpggamergirl:,

Thank you for the suggestion.

I ran the exe and I have attached the log.

Kindly help me in getting rid of this virus. Once i get rid of this virus i will buy some antivirus software.

Thank you
Combi-fix-log.txt
0
 

Author Comment

by:Excellearner
ID: 22913140
rpggamergirl:,

Attached is the screen shot of Bancos virus when i run anti spy from yahoo toolbar.

The attachement is after running combi fix.

thank you,


Bancos-Virus.doc
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 22914376
I'm not seeing any files relevant to Bancos trojan in the Combofix log(unless I missed something).
Looks like your scanner is false positively identifying your acer files/folders as bancos trojan, this happens to Avira also.

c:\acer\Empowering Technology <-- if the said bancos trojan is located in this directory(which looks like it according to the screenshot) then it's a false positive.

c:\windows\System32\Service <-- this folder is the only one I'm curious about, can you check the properties of that folder?


Do an online scan with Kaspersky as already suggested, if it doesn't find any viruses, then it would mean it's just a false positive.

0
 

Author Comment

by:Excellearner
ID: 22916014
rpggamergirl:

Thank you for the comment.

I am attaching the screen shots as requested.

And at times earlier to runing comby fix, the internet explorer would open a page on its owns. This is the reason i believe the bancos trojan is creating troube.

After running the combi fix, this is not happening.

thank you



services.txt
system-32-services.doc
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 22916160
Oh okay then, I thought after running combofix bancos was still causing trouble.

Combofix did delete some bad files,:(which would be the culprits)
The bancos screenshot of your antispy scanner is a false positive.

0
 

Author Comment

by:Excellearner
ID: 22916253
rpggamergirl:,

Ran the kaspersky online, but it did not list any threats.

Thank you,
0
 

Author Comment

by:Excellearner
ID: 22948979
rpggamergirl:

Is there anything else i need to do or should i close this.

Thank you
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 2000 total points
ID: 22949744
Sorry for my delayed reply.

Sounds good that Kaspersky scan is clean.

You may close this question now and uninstall combofix.
Go to Start > Run and copy and paste next command in the field:

ComboFix /u

The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
It will reset System Restore and will set a new, clean Restore Point.
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 22974956
Thank you for the points and the grade!
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To Remove Security Suite for Windows Malware from a Windows XP Machine:  Restart computer in Safe Mode (to do this see http://tinyurl.com/me78p) Login as Administrator Go to My Computer /Tools/ Folder Options/ View/  check mark the selectio…
If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question