Home→Descriptions→Trojan-Banker.Win32.Banker.ra
| Detected | May 11 2005 12:36 GMT |
| Released | May 11 2005 14:32 GMT |
File size of 676352 bytes.
Makes copies of itself with the following names once launched:
Ensures Using the system registry, system services or special system files, the program can launch itself or launch the creation of its files every time the Windows OS is subsequently booted autorun of the following installed files:
by adding values to autorun keys in the system registry:
[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ] "<file of source program >" = " Windows system directory (usually, C:\Windows\System32) %System%\lsass.scr"
Steals confidential user information from
A malicious program designed to steal user information related to banking and electronic payment systems and bank cards. The information is sent to a cybercriminal via email, ftp, the web or other methods.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792037the following banks, financial institutions, payment systems:
Connects to to the following Internet addresses:
Searches for the following windows:
| Title | Iexplorer |
Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.
Trojan-Banker.