Citadel Trojan
Citadel Trojan Description
Citadel Trojan – an Ironically-Named Bastion Against Bank Security
Citadel Trojan, as an upgraded and improved version of Keylogger Zeus, is built for and capable of all the basic functions that Keylogger Zeus is capable of – including recording your keyboard input (or keylogging), monitoring of financial websites like bankofamerica.com to steal relevant information, and scans of files that are likely to hold private data, such as passwords. Like Zeus, Citadel Trojan infects basic system processes to avoid detection; other than unusual resource usage by processes like svchost.exe, symptoms of Citadel Trojan’s attacks may not be very obvious or visible. Consequentially, SpywareRemove.com malware researchers strongly recommend that you use anti-malware programs to scan your PC on a regular basis as the best defense against potential Citadel Trojan attacks.
Citadel Trojan has also been given several updates that make Citadel Trojan even more dangerous than Keylogger Zeus. Many of these features are sold by Citadel Trojan’s criminal designers as separate add-ons that may or may not be present for any specific Citadel Trojan infection. Some significant additions include:
- Improved Chrome compatibility that allows Citadel Trojan to function in Chrome as well as other browsers (such as Internet Explorer and Firefox) that Zeus was already capable of handling.
- Support for increased evasion of anti-malware scanners on an update-by-update basis (although this support comes at a high price tag of nearly four hundred dollars initially and fifteen dollars per update).
- An unusual feature that may spell good news for some victims of Citadel Trojan attacks – an automatic shutdown function that triggers if Citadel Trojan detects a Russian or Ukrainian keyboard. The legal implications of this function strongly imply that Citadel Trojan’s designers may actually be based in one of these two regions.
The Social Side of Citadel Trojan’s Evolution
SpywareRemove.com malware researchers have also perceived that Citadel Trojan’s standout feature is most probably its marketing and social support for criminal clients. Because Citadel Trojan is designed and sold to other criminals as an expensive but potentially profitable malware kit, Citadel Trojan’s creators have placed heavy emphasis on providing long term support for their clients. Citadel Trojan has even included extra features that allow Citadel Trojan’s clients to communicate easily with the Citadel Trojan development team for the purpose of fixing bugs and suggesting features. This shift from the less-supported style of marketing that’s been in use by other keyloggers, such as ZeuS, is indicative that Citadel Trojan may be a threat to your PC for a very long time to come.
If you’ve recently used anti-malware scanners to cure a Citadel Trojan infection, you should be aware of the possibility that financial data and other types of personal info may have already been sent to Citadel Trojan’s client-end users. SpywareRemove.com malware experts recommend that you change all important passwords and other security-related information after resolving a Citadel Trojan problem, to insure that future account hijacks and other attacks are unable to take place.
Citadel Trojan Automatic Detection Tool (Recommended)
Is your PC infected with Citadel Trojan? To safely & quickly detect Citadel Trojan, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Citadel Trojan
What happens if Citadel Trojan does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name 1 %AllUsersProfile%\Application Data\Citadel Trojan 2 %UserProfile%\Start Menu\Programs\Startup\ .dll.lnk 3 %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ dll.lnk
Posted: January 27, 2012 | By SpywareRemove
Share:
Threat Level: 9/10
Rate this article:
Detection Count: 4,900


More
