Remove Banleed. Description and removal instructions

 
Title: Banleed

Type: Worms
Severity scale:Banleed severity is 53  (53 / 100)
 
Banleed is a worm that spreads through unprotected network shares. Once executed, the parasite installs itself to the system and starts a spreading routine. Then it updates itself via the Internet and attempts to download certain files. Banleed is designed for stealing user confidential information. The worm monitors web sites opened in Microsoft Internet Explorer or Mozilla Firefox. If the opened site has one of the predetermined addresses, Banleed hijacks the web browser and displays a fake page of the bank site. This page asks the user to provide bank account details and other sensitive information. Banleed runs on every Windows startup. It affects only those machines, which run the Portuguese version of the Windows operating system.


Banleed properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Banleed removal:

remover for Banleed

Banleed manual removal:

Kill processes:
nvsvc32.exe, system.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system
Delete files:
nvsvc32.exe, system.exe, system.bat
Misc:
Exact file location:
nvsvc32.exe - C:\Windows\System
system.exe, system.bat - C:\Windows

Other programs to remove Banleed:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 21/04/06
Information updated: 21/04/06

Additional resources related to Banleed:

Attention: If you know or you have a website or page about Banleed removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Banleed parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: