Home Malware Programs Trojans Trojan:BAT/Bancos.B

Trojan:BAT/Bancos.B

Posted: January 16, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 81
First Seen: January 16, 2013
OS(es) Affected: Windows

Trojan:BAT/Bancos.B is a Trojan that changes an affected computer's security settings by preventing alerts in Windows Security Center from occurring so that the computer is not informed if automatic Windows updates, antivirus program, or Windows Firewall are disabled. Once executed, Trojan:BAT/Bancos.B makes system changes by dropping potentially malicious files and making registry modifications. Trojan:BAT/Bancos.B creats the registry entry so that it can load automatically every time the PC user logs on. Trojan:BAT/Bancos.B may be installed on the compromised PC by other PC threats. Trojan:BAT/Bancos.B also disables System Restore in the affected computer system. Trojan:BAT/Bancos.B also disables User Account Control (UAC). Trojan:BAT/Bancos.B steals the victim's personal information and computer data and transmits his/her Windows user name and computer name to a remote server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



video-oral-de-paris-hilton-com-seu-atual-namorado-_ant_com_end.bat.SBOX File name: video-oral-de-paris-hilton-com-seu-atual-namorado-_ant_com_end.bat.SBOX
Size: 8.36 KB (8365 bytes)
MD5: 5ff82c9ccad37cc0a76bd8c0dcbc7fa1
Detection count: 84
Mime Type: unknown/SBOX
Group: Malware file
Last Updated: January 17, 2013
crash.bat File name: crash.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
ctfmon.exe File name: ctfmon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit" = "C:\Windows\system32\userinit.exe,%temp%\ctfmon.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "UpdatesDisableNotify" = "1"HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "FirewallDisableNotify" = "1"HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "AntiVirusDisableNotify" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "EnableLUA" = "0>"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings "DisableSR" = "1"
Loading...