Home Malware Programs Trojans Trojan-Banker.Win32.Bancos.ggl

Trojan-Banker.Win32.Bancos.ggl

Posted: January 15, 2010

Trojan-Banker.Win32.Bancos.ggl is a Trojan keylogger program that can steal confidential details like credit card numbers and other online banking details. Trojan-Banker.Win32.Bancos.ggl is capable of modifying the host file and restricting access to security websites. Trojan-Banker.Win32.Bancos.ggl may be installed via fake or misleading means, without the user's full awareness or agreement. Have Trojan-Banker.Win32.Bancos.ggl removed using a reliable anti-virus program.

Aliases

Mal/Generic-A (Sophos)
Win-Trojan/Bancos.339968.F (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
Loading...