How to Get Rid of the Banker Fox Virus

How to Get Rid of the Banker Fox Virus thumbnail
Removing infected files and programs

The "Banker Fox" virus is not what it appears to be based on the notifications it generates on a computer screen. The misleading messages stating that the computer is being attacked are actually from "Spyware protect 2009," which tries to persuade the user to download its software to block this virus. This is where the real problem occurs---"Spyware protect 2009" is what truly needs to be removed.

Instructions

    • 1

      Open the "Windows Task Manager" by pressing and holding down the Ctrl, Alt and Delete keys. Under the "Processes" tab, you'll find a list of programs that are being run on the computer. Locate "Banker Fox," left-click it once to select it, then left-click once on the "end process" button on the bottom right of the task manager. There are other processes that are also initiated by "Spyware protect 2009" that will need to be ended ---these include oranerkka, ooorjaas, irprokwks, otpeppggq, dkekkrkska, dkewiizkjdks, iddqdops, ienotas, iqmcnoeqz, jikglond, jiklagka, jrjakdsd, jungertab, kitiiwhaas, kkwknrbsggeg, klopnidret, krkdkdkee, krkmahejdk, aazalirt, krtawefg, krujmmwlrra, ktknamwerr, kuruhccdsdd, oropbbsee, otnnbektre, otowjdseww, rkaskssd, ronitfst, seeukluba, skaaanret, sysguardn, tobmygers, tobykke, zibaglertz, and sysguard, all of which end in the file type .exe.

    • 2

      Open the registry editor by left clicking once on "start" and left-click once on "run...." A message will pop up asking what the user wishes to open. A drop-down menu will be visible, so left-click it once and select the "regedit" option. The registry editor will now appear and will be divided into 2 sections. On the left side of the registry editor, left-click once on the small plus sign to expand the "HKEY_current user" heading.

    • 3

      Scroll down and look for "software," then left-click on the small plus sign to open it. Under the "software" heading, left-click once on AvScan, then left-click "edit" at the top of the registry editor and select "delete" to remove it. Also, delete "Spyware Protect 2009" from this section.

    • 4

      Go under the "software" heading and locate "Microsoft." Left-click once on "Microsoft," then left-click once on "windows" and left-click once on the "current version" title from underneath that heading. Select and delete "Run sysguardn." The remaining items to remove under the "Current version" heading are found under the "run" and "uninstall" categories. They are both titled "Spyware Protect 2009"; select and delete them.

    • 5

      Open the command prompt window by left-clicking once on "start" and left-click once on "run..." again, only this time type "CMD" in the field titled "open." Left-click once on "ok." Type in "regsvr32 /u vbzlib2.dll"---this will unregister "Banker Fox" from the DLL libraries.

    • 6

      Double-click on "my computer" to open it, then double-click again on the C drive. Look for "program files" and double-left-click it. Under "program files," look for any files that contain "Spyware Protect 2009" in the title, left-click each one once to select, then left-click once on "file" and once on "delete" to remove the unwanted malicious files. Left-click once on the "back" button at the top to exit the "program files".

    • 7

      Look for the "windows" heading and double-left-click to open it. Delete the following .exe files under the "windows" heading: oranerkka, ooorjaas, irprokwks, otpeppggq, dkekkrkska, dkewiizkjdks, iddqdops, ienotas, iqmcnoeqz, jikglond, jiklagka, jrjakdsd, jungertab, kitiiwhaas, kkwknrbsggeg, klopnidret, krkdkdkee, krkmahejdk, aazalirt, krtawefg, krujmmwlrra, ktknamwerr, kuruhccdsdd, oropbbsee, otnnbektre, otowjdseww, rkaskssd, ronitfst, seeukluba, skaaanret, sysguardn, tobmygers, tobykke, zibaglertz, and sysguard. These are the same files that were previously halted by using the Windows Task Manager.

Tips & Warnings

  • If you have spyware software on your computer already, you may want to use it to block sites from which the virus comes, including: swp2009.com, spyprotect2009.com, sp-protect2009.com, sys-protection.com, sysguard2009.com, os-protection.com, spy-protect-2009.com, spywprotect.com, adwareguard.net, antivirus-win.com, spywrprotect-2009.com, sysprotect.net, spwprotect2009.com, spy-protec.com, spyware-protector-2009.com, browser-security.microsoft.com, antiwareprotect.com and antivguardian.com.

Related Searches:

References

  • Photo Credit ajuda ! virus! image by Mauro Rodrigues from Fotolia.com

Comments

You May Also Like

Related Ads

Featured