Home Malware Programs Worms Mailbancos

Mailbancos

Posted: March 28, 2006

Mailbancos is an Internet worm that propagates by e-mail. It comes in HTML messages with embedded links that download and install a dangerous trojan, which steals passwords the user enters into many web forms. Mailbancos sends stolen data to its author by e-mail. The worm distributes malicious messages to all the contacts from the Windows Address Book. A typical e-mail is in Portuguese.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iexplore.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinlogon32_
Loading...