Home Malware Programs Trojans Mal/BankSpy-C

Mal/BankSpy-C

Posted: June 1, 2011

Mal/BankSpy-C is a hazardous computer trojan that is able to steal confidential data stolen from an infected computer and then transmit it to a remote server. Mal/BankSpy-C invades and installs the compromised computer system without a victim's knowledge or authorization when he/she opens unidentified email attachment or image, uses instant messaging, etc. Mal/BankSpy-C downloads corrupt files from the web to harm the PC system. Mal/BankSpy-C runs system scanners after a computer starts up and displays security alerts at set intervals. Mal/BankSpy-C should be removed from a computer once it's detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Program Files%\Mal/BankSpy-C\Mal/BankSpy-C.exe
    2 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Mal/BankSpy-C.lnk
    3 %UserProfile%\Desktop\Mal/BankSpy-C.lnk
    4 %UserProfile%\Start Menu\Mal/BankSpy-C\Help.lnk
    5 %UserProfile%\Start Menu\Mal/BankSpy-C\Mal/BankSpy-C.lnk
    6 %UserProfile%\Start Menu\Mal/BankSpy-C\Registration.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\13376694984709702142491016734454HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "13376694984709702142491016734454?
Loading...