Home Malware Programs Trojans Banklis

Banklis

Posted: March 28, 2006

Banklis is a trojan that monitors user Internet activity in attempt to detect certain online banking services. Once the user enters such sites, the trojan begins to record all the keystrokes in order to steal user account details. Gathered data may be stealthily transferred to the remote attacker. Banklis automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 perfhmon.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunperfhmon
Loading...