Banta Ransomware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jefflbi, Jan 29, 2022.

  1. jefflbi

    jefflbi Private First Class

    Woke up this morning to find my pc had been compromised by ransomware that encrypts every file with the extension .banta. What is best course of action?? Thanks in advance........
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jefflbi

    jefflbi Private First Class

    Thanks much........... I am running the steps in the pinned post to remove malware. I will try the tool in your link when that is completed.......
     
  4. jefflbi

    jefflbi Private First Class

    I am uploading the Roguekiller repost as specified in the malware removal instructions.........
     

    Attached Files:

  5. jefflbi

    jefflbi Private First Class

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did...but we prefer that you do all the requested scans and then attach them.
     
  7. jefflbi

    jefflbi Private First Class

    The "analyze.exe" of MGtools has been running for hours............. Hitman pro found no infections........
     
  8. jefflbi

    jefflbi Private First Class

    Uploaded log files as requested, HitmanPro did not find any infections.........
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For MGtools, did you save MGtools.exe to C:\MGtools.exe as requested. It must be save to the root folder of your Windows boot drive. Do not save it anywhere else and do not attempt to Run or Open it from the download link. You must save it to your PC. Please try again and make sure you follow the instructions exactly. If you get any error messages, see if it is one of the ones that are explained on the download page. If the error is not on the download page, give us the exact word for word message.


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  10. jefflbi

    jefflbi Private First Class

    Yes I did install in the root of C as specified and then ran the exe. I am repeating that procedure and will reply when the program finishes.
     
  11. jefflbi

    jefflbi Private First Class

    I'm sorry, I didn't there was a zip file of the logs. I only attached the one txt file. Here is the complete zip file.
     

    Attached Files:

  12. jefflbi

    jefflbi Private First Class

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then if Trend Micro didn't give you a decryption tool, your only option is to restore from a back up or reinstall. You can post in the software forum for advice on how to do either.
     
  14. jefflbi

    jefflbi Private First Class

    Just an FYI, I think this site might be better as it includes all of the tools available on the Trend Micro site along with many others. And this site is most likely to post a tool for .banta ransomeware as soon as one is developed...……..

    Home | The No More Ransom Project
     
  15. jefflbi

    jefflbi Private First Class


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds