Remove Banleed.b. Description and removal instructions

 
Title: Banleed.b

Type: Worms
Severity scale:Banleed.b severity is 58  (58 / 100)
 
Banleed.b is a worm that spreads through unprotected network shares. Once executed, the parasite installs itself to the system and starts a spreading routine. Then it updates itself via the Internet and attempts to download certain files. Banleed.b is designed for stealing user confidential information. The worm monitors web sites opened in Microsoft Internet Explorer or Mozilla Firefox. If the opened site has one of the predetermined addresses, Banleed.b hijacks the web browser and displays a fake page of the bank site. This page asks the user to provide bank account details and other sensitive information. Stolen data is sent to a predetermined e-mail address. Banleed.b runs on every Windows startup. It affects mostly machines running Portuguese and Spanish versions of the Windows operating system.


Related files: lsass.exe, system.bat

Banleed.b properties:
• Sends out logs by FTP or email
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Banleed.b removal:

remover for Banleed.b

Banleed.b manual removal:

Kill processes:
lsass.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lsass.exe
Delete files:
lsass.exe, system.bat
Misc:
Banleed.b files reside in the C:\Windows\System folder.

Other programs to remove Banleed.b:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 29/06/06
Information updated: 29/06/06

Additional resources related to Banleed.b:

Attention: If you know or you have a website or page about Banleed.b removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Banleed.b parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: