Home Malware Programs Trojans Trojan.Downloader.Banload.ARZ

Trojan.Downloader.Banload.ARZ

Posted: March 29, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 237
First Seen: March 29, 2013
Last Seen: January 23, 2022
OS(es) Affected: Windows

Trojan.Downloader.Banload.ARZ is a Trojan that downloads other files on the compromised PC. If a computer user has a Battle.net account, TrojanDownloader:Win32/Banload.ARZ deletes an account information by deleting the data in the registry subkey or may make it not work as expected. When installed, Trojan.Downloader.Banload.ARZ makes system changes by dropping potentially malicious files and making registry modifications. Trojan.Downloader.Banload.ARZ creates the registry entry so that the downloaded file can automatically run every time Windows is started. Trojan.Downloader.Banload.ARZ checks if the targeted computer is connected to the Internet. If so, Trojan.Downloader.Banload.ARZ connects to the specific servers to download a certain file. Trojan.Downloader.Banload.ARZ enables processes to run with elevated privileges. Trojan.Downloader.Banload.ARZ changes the registry entry so that any elevated action is executed without urging the computer user.

Aliases

Heur.Suspicious [Comodo]W32/FakeAlert.FT.gen!Eldorado [F-Prot]Artemis!57844157AC48 [McAfee]BackDoor.Siggen.51461 [DrWeb]RDN/Generic.dx!hc [McAfee]Trj/Injector.AV [Panda]Startpage.TBB [AVG]W32/VBKrypt.PEJC!tr [Fortinet]Trojan.Win32.VBKrypt [Ikarus]TR/Graftor.69097.1 [AntiVir]Trojan.Win32.VBKrypt.pejc [Kaspersky]WS.Reputation.1 [Symantec]Artemis!B2F23B6591BF [McAfee]Generic19.AJIJ [AVG]Trojan.Win32.Refroso [Ikarus]
More aliases (85)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Nokia\weed.exe File name: weed.exe
Size: 5.12 MB (5127680 bytes)
MD5: 57844157ac487e4957299ad6f913b244
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Nokia
Group: Malware file
Last Updated: August 30, 2019
C:\Users\<username>\AppData\Roaming\6FB4.exe File name: 6FB4.exe
Size: 88.8 KB (88800 bytes)
MD5: df5fa3783d3f69f17e6859f8018b8b6e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\6FB4.exe
Group: Malware file
Last Updated: March 15, 2022
%WINDIR%\system32\SMSvcHost.exe File name: SMSvcHost.exe
Size: 217.08 KB (217088 bytes)
MD5: 780570b465faf1ff329f15493fa5b946
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 29, 2013
%APPDATA%\Java\r4s5fgv154e6r1f6we.exe File name: r4s5fgv154e6r1f6we.exe
Size: 118.27 KB (118272 bytes)
MD5: 8bdb6531c7b03cce7f6357074ed1b664
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Java
Group: Malware file
Last Updated: April 2, 2013
Loading...