Home Malware Programs Trojans PWSteal.Banker.N

PWSteal.Banker.N

Posted: December 5, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 1,274
First Seen: December 5, 2011
Last Seen: June 9, 2022
OS(es) Affected: Windows

PWSteal.Banker.N is a banking Trojan that invades the affected computer without your permission and knowledge. PWS:Win32/Banker.N is a Trojan that comes from the Win32/Banker family that steals banking data and gathers confidential information. Once executed, PWSteal.Banker.N might slow down your computer and decrease PC performance. PWSteal.Banker.N allows attackers to gain remote access and control over the infected machine. PWSteal.Banker.N can be used to trace and steal information entered onto the compromised PC and might drop malicious programs. PWSteal.Banker.N is able to create a browser helper object (BHO) in the Internet Explorer. Although BHOs are not malicious, they might be used to hijack web browsers, and PWSteal.Banker.N is able to do this. PWSteal.Banker.N modifies and uses the names of the original files to hide itself on the targeted computer system. The purpose of PWSteal.Banker.N is to record sensitive details such as account numbers, passwords and CVV/CVV2 and send them to remote attackers.

Aliases

Generic Malware [Panda]PSW.Banker6.NWH [AVG]W32/Farko.X!tr [Fortinet]Trojan/Win32.Farko.gen [Antiy-AVL]Trojan.PWS.Spy.13156 [DrWeb]Trojan.Generic.6857214 [BitDefender]Trojan-Spy.Win32.Farko.x [Kaspersky]Win32:Malware-gen [Avast]Trojan.ADH [Symantec]Generic PWS.y!dsb [McAfee]TrojanSpy.Farko.x [CAT-QuickHeal]Trojan-Spy.Win32.Savnut [Ikarus]WS.Reputation.1 [Symantec]PSW.Banker6.LTM [AVG]W32/Banker.WYC!tr.spy [Fortinet]
More aliases (64)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\AdobeFlash\AdobeFlash.exe File name: AdobeFlash.exe
Size: 2.04 MB (2041856 bytes)
MD5: cf282acc0612524ecf699e31637a1fd4
Detection count: 586
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\AdobeFlash
Group: Malware file
Last Updated: June 16, 2016
%APPDATA%\AdobeFlash\AdobeFlash.exe File name: AdobeFlash.exe
Size: 7.29 MB (7293440 bytes)
MD5: b123b6d118fc916ff8776346a0be9751
Detection count: 248
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\AdobeFlash
Group: Malware file
Last Updated: June 16, 2016
C:\Users\<username>\AppData\Roaming\AdobeFlash\AdobeFlash.exe File name: AdobeFlash.exe
Size: 2.04 MB (2041856 bytes)
MD5: e2229e4dbc7f83e8ad132928bcdb5d99
Detection count: 208
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\AdobeFlash\AdobeFlash.exe
Group: Malware file
Last Updated: June 9, 2022
%APPDATA%\AdobeFlash\AdobeFlash.exe File name: AdobeFlash.exe
Size: 7.35 MB (7358976 bytes)
MD5: 9e196f3bdab466cc43500441e690b653
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\AdobeFlash
Group: Malware file
Last Updated: June 16, 2016
%APPDATA%\adobeflash\adobeflash.exe File name: adobeflash.exe
Size: 40.91 KB (40918 bytes)
MD5: 555a2549d1dd86f719a3697ce314e76f
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\adobeflash
Group: Malware file
Last Updated: June 16, 2016
%APPDATA%\AcroIEHelpe051.dll File name: AcroIEHelpe051.dll
Size: 285.64 KB (285648 bytes)
MD5: dc23fc5d2d73b0499ba9166ff9cb9bf2
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%
Group: Malware file
Last Updated: December 6, 2011
Loading...