English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Banker.Win32.Banker.ezn

Detected Oct 11 2007 19:27 GMT
Released Oct 12 2007 12:59 GMT

This is a description which has been automatically generated following analysis of this program on a test machine. This description may contain incomplete or inaccurate information.

Summary


Technical details

File size of 96256 bytes.


Malicious activity

Steals confidential user information from A malicious program designed to steal user information related to banking and electronic payment systems and bank cards. The information is sent to a cybercriminal via email, ftp, the web or other methods.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792037
the following banks, financial institutions, payment systems
:

  • Halifax PLC
  • Caja Mar
  • Hellenic Bank
  • Sparkasse
  • Newcastle Permanent Building Society
  • Wells Fargo Bank
  • BRE Bank S.A.
  • Fortis Banque Luxembourg
  • St.George Bank
  • NORD/LB Norddeutsche Landesbank
  • E*TRADE FINANCIAL
  • Data Processing Center and IT-Service Provider
  • Caja Madrid
  • Banco de Valencia
  • Banco Santander group
  • Gruppo Banca Carige
  • ScotiaBank
  • Co-Operative Bank
  • Volksbank
  • Lloyds TSB Bank
  • Citibank
  • Landesbank Baden-Wurttemberg (BW-Bank)
  • Poste Italiane
  • First Trust Bank
  • Adelaide Bank
  • HSBC Group
  • Visa
  • ABN AMRO banking group
  • Sanpaolo IMI SpA
  • ING Bank
  • Bank Of America
  • Banca Intesa SpA
  • CommonWealthBank
  • SEB Bank
  • The Suncorp Group
  • Smile Internet Bank
  • BNP Paribas
  • Barclays Bank PLC
  • Deutsche Bank
  • RAS Bank
  • Westpac Banking Corporation
  • Dresdner Bank
  • Alliance & Leicester
  • Banesto
  • Royal Bank of Scotland (RBS)
  • Banca Generali
  • Noris Bank
  • Postepay

Creates unique identifiers to flag its presence in the system

  • Helper


Other activities

Modifies the system registry keys:

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Helper ] "DName" = "­­"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Helper ] "GUID" = "lVUV%#V"R:&""U:#$$v:.S'V:#/$" "#S$.&"j"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915} ] "(default)" = "Editor plugin"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\InprocServer32 ] "(default)" = "pecker.dll"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\InprocServer32 ] "ThreadingModel" = "Apartment"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\ProgID ] "(default)" = "Soap.1"

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\TypeLib ] "(default)" = "{5B39702E-3389-451b-B7D7-E0CBC123BC2B}"

Deletes the following files on an infected computer:

  • <­path to source program­><­file of source program ­>
  • Windows system directory (usually, C:\Windows\System32) %System%\cookie.dat
  • Windows system directory (usually, C:\Windows\System32) %System%\bb.dat
  • Windows system directory (usually, C:\Windows\System32) %System%\ps.dat
  • Windows system directory (usually, C:\Windows\System32) %System%\di.gif
  • Windows system directory (usually, C:\Windows\System32) %System%\dr.gif
  • Windows system directory (usually, C:\Windows\System32) %System%\boa.dat


Bookmark and Share
Share
Trojan-Banker

Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.


Other versions

Aliases

Trojan-Banker.Win32.Banker.ezn (Kaspersky Lab) is also known as:

  • Trojan-Spy.Win32.Banker.ezn (Kaspersky Lab)
  • Mal/Behav-112 (Sophos)
  • TrojanDropper:Win32/Banker.USX (MS(OneCare))
  • Generic.Spy.Finanz.6AC0EE21 (BitDef7)
  • Trojan.DR.BHO.Gen (VirusBuster)
  • Win32:Banker-COC (AVAST)
  • Trojan-Spy.Win32.Banker (Ikarus)
  • BHO.ANZ (AVG)
  • TR/Drop.Banke.cnx.2 (AVIRA)
  • Infostealer.Banker.D (NAV)
  • Generic.dx (NAI)
  • Trojan.Spy.Win32.Banker.ezn (Rising)