Symantec antivirus detects the file as Downloader.Bancos. It is used when detecting many individual but varied downloaders of the Infostealer.Bancos Trojan, for which specific definitions have not been created.
The Trojan typically attempts to connect to a network location through HTTP or FTP and download a copy of the Infostealer.Bancos Trojan to the compromised computer. The Trojan then executes it.
Scan for and delete the infected files:
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
Run a full system scan.
If any files are detected, take note of the file names and click Delete.
Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:
Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.
4. To clear the Temporary Internet Files folder, if required
Log on to the computer using the name that was shown in the path that you wrote down in during the scan and delete section.
For example, if the path was:
C:\Documents and Setting\user-xyz\Local Settings\Temporary Internet Files\qrwmqczd.dll
log on to the computer as user-xyz.
Start Internet Explorer.
Click Tools > Internet Options.
In the Temporary Internet Files section, click the Delete Files button.
Check Delete all offline content, and then click OK.
.:: Malicious Brains ::.
http://maliciousbrains.blogspot.com
|