Home→Descriptions→Trojan-Banker.Win32.Banker.ezn
| Detected | Oct 11 2007 19:27 GMT |
| Released | Oct 12 2007 12:59 GMT |
File size of 96256 bytes.
Steals confidential user information from
A malicious program designed to steal user information related to banking and electronic payment systems and bank cards. The information is sent to a cybercriminal via email, ftp, the web or other methods.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792037the following banks, financial institutions, payment systems:
Creates unique identifiers to flag its presence in the system
Modifies the system registry keys:
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Helper ] "DName" = ""
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Helper ] "GUID" = "lVUV%#V"R:&""U:#$$v:.S'V:#/$" "#S$.&"j"
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915} ] "(default)" = "Editor plugin"
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\InprocServer32 ] "(default)" = "pecker.dll"
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\InprocServer32 ] "ThreadingModel" = "Apartment"
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\ProgID ] "(default)" = "Soap.1"
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Classes\CLSID\{ABA24A5E-155B-433a-9D0A-4835754D3915}\TypeLib ] "(default)" = "{5B39702E-3389-451b-B7D7-E0CBC123BC2B}"
Deletes the following files on an infected computer:
Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.
Trojan-Banker.