Home Malware Programs Trojans Trojan.Banker

Trojan.Banker

Posted: October 16, 2006

Threat Metric

Threat Level: 9/10
Infected PCs: 16,908
First Seen: July 24, 2009
Last Seen: August 13, 2024
OS(es) Affected: Windows

Trojan.Banker, which is related to Banload and Downloader.Banload, may install itself on your PC through a browser exploit or some other form of trickery. Once installed, Trojan.Banker parasite will monitor your searches and will intercept passwords to several major banking websites when you type them in. Trojan.Banker opens up a large security hole on your computer and is a very dangerous threat to the security of your personal and financial data.

Aliases

Trojan-Banker.Win32.Agent.axd [Kaspersky]PSW.Banker5.BEUT [AVG]Win32:Banker-GRX [Avast]Sus/Behav-269 [Sophos]Generic PWS.y!coe [McAfee]Trojan-Banker.Win32.Banker.bbqq [Kaspersky]BC.Heuristics.Rootkit.B-7.MV [ClamAV]Win32.Spy.Banker.Prq [eSafe]a variant of Win32/Spy.Banker.PRQ [NOD32]Artemis!E27E6549AD9C [McAfee]Artemis!EF1AAF78FB4E [McAfee]Mal/VB-BL [Sophos]TSPY_BANKER.OGS [TrendMicro]Trojan.Win32.Malware [Sunbelt]Win32/Spy.Banker.AKGG [NOD32]
More aliases (1060)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft Windows\taskWin.exe File name: taskWin.exe
Size: 1.94 MB (1942016 bytes)
MD5: 9b6bf5b960ebd4d8ebe92089d670fd4c
Detection count: 7,059
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft Windows\taskWin.exe
Group: Malware file
Last Updated: February 9, 2025
c:\windows\temp\_avg_\unp199856236.tmp File name: unp199856236.tmp
Size: 40.44 KB (40448 bytes)
MD5: f8c0ba1568f1936e9861f1dfcc0b7bec
Detection count: 714
File type: Temporary File
Mime Type: unknown/tmp
Path: c:\windows\temp\_avg_
Group: Malware file
Last Updated: July 31, 2020
C:\Users\<username>\Desktop\Pai\drive controle\USB Vibration Joystick(07.exe File name: USB Vibration Joystick(07.exe
Size: 1.41 MB (1417554 bytes)
MD5: c16a3c32a5d0895fbaf3a76f0c264a45
Detection count: 211
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Pai\drive controle\USB Vibration Joystick(07.exe
Group: Malware file
Last Updated: May 18, 2024
%APPDATA%\MacromediaFlesh\MacromediaFlesh.exe File name: MacromediaFlesh.exe
Size: 2.25 MB (2256896 bytes)
MD5: 7eea4697ab8c6930138e5cbbce938e04
Detection count: 194
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\MacromediaFlesh
Group: Malware file
Last Updated: January 26, 2017
Yinnet00.exe File name: Yinnet00.exe
Size: 544.25 KB (544256 bytes)
MD5: bf6ae02c41d732cc3542fcd7c9611a84
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 6, 2010
%WINDIR%\System32\drivers\E63D9ACC.sys File name: E63D9ACC.sys
Size: 9.21 KB (9216 bytes)
MD5: e27e6549ad9c53de39541f6fc7625394
Detection count: 71
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 30, 2010
%USERPROFILE%\Documents\fccccddd\ctfmon.exe File name: ctfmon.exe
Size: 2.46 MB (2464256 bytes)
MD5: c7c7d11b94e13af0b34facef9207d625
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents\fccccddd
Group: Malware file
Last Updated: July 30, 2016
%PROGRAMFILES%\Anti Sansur\AntiSansur.exe File name: AntiSansur.exe
Size: 622.08 KB (622080 bytes)
MD5: 9491aa6af1e6b0383536d61f590819f8
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Anti Sansur
Group: Malware file
Last Updated: December 7, 2010
services.exe File name: services.exe
Size: 640.51 KB (640512 bytes)
MD5: ee55496b41c6c850fe5fcbc2de21d73c
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 7, 2010
%WINDIR%\system32\dwin.exe File name: dwin.exe
Size: 768 KB (768000 bytes)
MD5: a5d003e7727e8c38cd847c778f2a8321
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: October 20, 2010
aecces.exe File name: aecces.exe
Size: 35.32 KB (35328 bytes)
MD5: 75f943c9778e3397aaedadff89c430bf
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 1, 2010
c:\drivers\nl4.exe File name: nl4.exe
Size: 667.64 KB (667648 bytes)
MD5: 56dd7e2825a8f60db0966830bc936f76
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: c:\drivers
Group: Malware file
Last Updated: October 27, 2010
c:\drivers\nl7.exe File name: nl7.exe
Size: 1.61 MB (1611776 bytes)
MD5: 875209f1fcd5c214c92050eeab3215aa
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: c:\drivers
Group: Malware file
Last Updated: October 27, 2010
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Accessories\servicesnb.exe File name: servicesnb.exe
Size: 63.63 MB (63636363 bytes)
MD5: 690d7c1839ddb7c47a9a6b63a51c8b14
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Accessories
Group: Malware file
Last Updated: March 26, 2016
winnt4.exe File name: winnt4.exe
Size: 669.18 KB (669184 bytes)
MD5: 4e5dc8cb901d5e33466d48f0a54849e8
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 1, 2010
appconf32.exe File name: appconf32.exe
Size: 47.61 KB (47616 bytes)
MD5: 030ee66e1d914bab33c82b9149008efc
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 10, 2010
c:\drivers\nl3.exe File name: nl3.exe
Size: 1.89 MB (1892352 bytes)
MD5: e53152dbb05761d56dc9adfad7fa9ee5
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: c:\drivers
Group: Malware file
Last Updated: October 28, 2010
%WINDIR%\system32\netsvcs32.exe File name: netsvcs32.exe
Size: 695.29 KB (695296 bytes)
MD5: 68ef39373a779cd6e9333a916a0cfffe
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 7, 2010
%SystemDrive%\Users\<username>\AppData\Roaming\msobjut.exe File name: msobjut.exe
Size: 64.51 KB (64512 bytes)
MD5: 6cc3760e6cb027ada2fa7e49feed7b48
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: October 29, 2019
%USERPROFILE%\AppData\uTorrent\necomp.bin.exe File name: necomp.bin.exe
Size: 1.25 MB (1255104 bytes)
MD5: 90bba3b6d0a6daa31fc54137922214dc
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\AppData\uTorrent
Group: Malware file
Last Updated: March 23, 2015
hostne.exe File name: hostne.exe
Size: 36.86 KB (36864 bytes)
MD5: 6a6c511058beea2c9b8580d5651a51d8
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 18, 2010

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathwinnt4.exewinnt5.exexlr.exeRun keyswinnt2winnt3winnt4winnt5winnt7

Additional Information

The following directories were created:
%APPDATA%\BLozhitheto KUachoundefinedu

Related Posts

One Comment

Loading...