Home Malware Programs Trojans Infostealer.Banprox

Infostealer.Banprox

Posted: October 5, 2011

Threat Metric

Ranking: 16,219
Threat Level: 9/10
Infected PCs: 881
First Seen: October 5, 2011
Last Seen: February 17, 2025
OS(es) Affected: Windows

Infostealer.Banprox is a Trojan infection that redirects network traffic from specific websites, usually banks, to a malicious proxy in order to steal personal information from the infected computer. Once installed, Infostealer.Banprox adds some system files and modifies the registry in order to download a configuration script from a remote server, which includes a list of the affected websites and the malicious proxy. It is strongly recommended to remove Infostealer.Banprox immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Emotion[NUMBER].exe File name: Emotion[NUMBER].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[NAME].jpg.exe File name: [NAME].jpg.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[APP_NAME]_setup_[RANDOM CHARACTERS].exe File name: [APP_NAME]_setup_[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
FOTO-[RANDOM CHARACTERS].exe File name: FOTO-[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
sys32config.dll File name: sys32config.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"
Loading...