Home Malware Programs Trojans TrojanSpy:Win32/Banker.AJC

TrojanSpy:Win32/Banker.AJC

Posted: September 13, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 30
First Seen: September 13, 2012
Last Seen: January 22, 2020
OS(es) Affected: Windows

TrojanSpy:Win32/Banker.AJC is a data-stealing Trojan that is a DLL component of the Win32/Banker family. TrojanSpy:Win32/Banker.AJC steals online banking credentials such as account login names and passwords, log keystrokes and sends the gathered information to remote attackers. Mostly, TrojanSpy:Win32/Banker.AJC targets customers of Brazilian banks. TrojanSpy:Win32/Banker.AJC is distributed onto the affected computer by other malware threats, often by variants of the Win32/Banload family. TrojanSpy:Win32/Banker.AJC creates its start-up registry entry so that it can load automatically every time Windows boots. TrojanSpy:Win32/Banker.AJC is installed onto the targeted computer together with other files that may be configuration files or other variations of the families of Win32/Banker or Win32/Banload. If TrojanSpy:Win32/Banker.AJC finds these configuration files on your machine, it will read and decrypt them. While being decrypted, these other files may also be recognized as other malware threats.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Startup Folder%\netsecurity.cpl File name: %Startup Folder%\netsecurity.cpl
Mime Type: unknown/cpl
Group: Malware file
%APPDATA%\drivers\ablxm.dll File name: %APPDATA%\drivers\ablxm.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%APPDATA%\drivers\rtl2108.rtl File name: %APPDATA%\drivers\rtl2108.rtl
Mime Type: unknown/rtl
Group: Malware file
%APPDATA%\drivers\rtl856l.vxd File name: %APPDATA%\drivers\rtl856l.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl8704.vxd File name: %APPDATA%\drivers\rtl8704.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl9976.vxd File name: %APPDATA%\drivers\rtl9976.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl256.vxd File name: %APPDATA%\drivers\rtl256.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl3264.vxd File name: %APPDATA%\drivers\rtl3264.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl6432.vxd File name: %APPDATA%\drivers\rtl6432.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl745G.vxd File name: %APPDATA%\drivers\rtl745G.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl8192.vxd File name: %APPDATA%\drivers\rtl8192.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\drivers\rtl8194.vxd File name: %APPDATA%\drivers\rtl8194.vxd
Mime Type: unknown/vxd
Group: Malware file
%APPDATA%\Microsoft\Windows\netsecurity.cpl File name: %APPDATA%\Microsoft\Windows\netsecurity.cpl
Mime Type: unknown/cpl
Group: Malware file
%APPDATA%\Microsoft\Windows\kb8532.scr File name: %APPDATA%\Microsoft\Windows\kb8532.scr
Mime Type: unknown/scr
Group: Malware file
Loading...