Bancos Virus

Dear Experts,

My laptop has become infected with Bancos virus. Does this forum have any solution for the removal of the virus.

What are the possible alternatives.

Thank you,
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.


 I would recommend that you use the on line Anti-virus scan from Kaspersky

I would also recommend downloading and updating malwarebytes.
You can get it free from
Once updated, reboot into Safe Mode (F8 at startup) and run a scan.
You should do this with your current antivirus product as well.
ExcellearnerAuthor Commented:

Does your suggestions by runing the urls clean the virus from laptop orjust identify the virus.

Do i need take a back and how do i do it.

My laptop is acer aspire 5720.

Thank you
Exploring ASP.NET Core: Fundamentals

Learn to build web apps and services, IoT apps, and mobile backends by covering the fundamentals of ASP.NET Core and  exploring the core foundations for app libraries.


I it cannot remove the virus try some a sollution from another AV

This virus is pretty old so it should be removed by any AV you're using (suggest you do a full scan)

ExcellearnerAuthor Commented:

thank you for the email and sorry to come back to you on the same questuion.

Does the software in the above url remove the virus or just detect.

Which av sotware do you recommend for house hold purpose. I visit type of websites. SO i need a comprehensive solution.

Thank you

Checked and on Kaspersky's site it says that it just detects but do not remove
If your AV do not work you might want to try this I tryied and it's prety ok as a home AV

If Malwarebytes or Kaspersky free trial or other scanners already mentioned fails to remove it, then try Combofix (we need to see the logfile afterwards so we can make a script to remove any files not removed in the first run)

Please download ComboFix by sUBs:

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ExcellearnerAuthor Commented:

Thank you for the suggestion.

I ran the exe and I have attached the log.

Kindly help me in getting rid of this virus. Once i get rid of this virus i will buy some antivirus software.

Thank you
ExcellearnerAuthor Commented:

Attached is the screen shot of Bancos virus when i run anti spy from yahoo toolbar.

The attachement is after running combi fix.

thank you,

I'm not seeing any files relevant to Bancos trojan in the Combofix log(unless I missed something).
Looks like your scanner is false positively identifying your acer files/folders as bancos trojan, this happens to Avira also.

c:\acer\Empowering Technology <-- if the said bancos trojan is located in this directory(which looks like it according to the screenshot) then it's a false positive.

c:\windows\System32\Service <-- this folder is the only one I'm curious about, can you check the properties of that folder?

Do an online scan with Kaspersky as already suggested, if it doesn't find any viruses, then it would mean it's just a false positive.

ExcellearnerAuthor Commented:

Thank you for the comment.

I am attaching the screen shots as requested.

And at times earlier to runing comby fix, the internet explorer would open a page on its owns. This is the reason i believe the bancos trojan is creating troube.

After running the combi fix, this is not happening.

thank you

Oh okay then, I thought after running combofix bancos was still causing trouble.

Combofix did delete some bad files,:(which would be the culprits)
The bancos screenshot of your antispy scanner is a false positive.

ExcellearnerAuthor Commented:

Ran the kaspersky online, but it did not list any threats.

Thank you,
ExcellearnerAuthor Commented:

Is there anything else i need to do or should i close this.

Thank you
Sorry for my delayed reply.

Sounds good that Kaspersky scan is clean.

You may close this question now and uninstall combofix.
Go to Start > Run and copy and paste next command in the field:

ComboFix /u

The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
It will reset System Restore and will set a new, clean Restore Point.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Thank you for the points and the grade!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.