Home Malware Programs Trojans Trojan-Banker.Win32.Banker.auzi

Trojan-Banker.Win32.Banker.auzi

Posted: April 21, 2011

Trojan-Banker.Win32.Banker.auzi is a malicious computer that opens up a large security hole on a computer system and is a very dangerous threat to the security of your confidential data, such as personal and financial information. Trojan-Banker.Win32.Banker.auzi may be remotely monitored by an anonymous hacker and Trojan Banker repair and update itself, making it difficult to manually eliminate. Trojan-Banker.Win32.Banker.auzi has to be
removed from a targeted machine upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\islup.exe
    2 %System%\islupc.exe
    3 %System%\islupj.exe
    4 c:\%ComputerName%.txt
    5 c:\tyu.txt
    6 c:\wabs.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\uxPtgYTxHKEY_LOCAL_MACHINE\SOFTWARE\DescriptionHKEY_LOCAL_MACHINE\SOFTWARE\Description\MicrosoftHKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft\RpcHKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft\Rpc\UuidTemporaryDataHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\ClientHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client\SuperSocketNetLibHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client\SuperSocketNetLib\LastConnect
Loading...