Home Malware Programs Trojans JAVA_BANKER.ZIP

JAVA_BANKER.ZIP

Posted: June 3, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 62
First Seen: June 3, 2013
OS(es) Affected: Windows

JAVA_BANKER.ZIP is a Java Trojan that propagates via hacked government websites of Brazil together with TSPY_BANKER.ZIP. JAVA_BANKER.ZIP is spread as an alleged image program (.gif file) detected as JAVA_BANKER.ZIP within the affected computer's short-lived folder. The .gif file represents a Java file installed with the help of the 'javaw.exe' that's involved inside the Java Runtime Scenario. Commands are issued to JAVA_BANKER.ZIP for downloading and running program files via numerous pre-set domains. Once JAVA_BANKER.ZIP gains admission into the victimized computer system, the affected PC user loses his/her administrative privileges to the machine, thus allowing JAVA_BANKER.ZIP to infect the computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



javaw.exe File name: javaw.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...