Home Malware Programs Trojans TrojanDownloader:Win32/Banload.AIB

TrojanDownloader:Win32/Banload.AIB

Posted: February 6, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 18
First Seen: February 6, 2013
OS(es) Affected: Windows

TrojanDownloader:Win32/Banload.AIB is a Trojan that downloads and executes other PC threats on the compromised PC. Once installed, TrojanDownloader:Win32/Banload.AIB makes system changes by displaying the PowerPoint slide and dropping potentially malicious files. When TrojanDownloader:Win32/Banload.AIB runs, it loads the malicious .bat file, which opens and displays the PowerPoint presentation .pps file, possibly to block PC users from noticing its existence, at the same time running the executable file (.exe) in the background. TrojanDownloader:Win32/Banload.AIB downloads the configuration file, which includes a list of locations from which to download other, potentially malicious, files.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 342.01 KB (342016 bytes)
MD5: 1c1f8d68b370c5b279c9c01a670aa68d
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
Helper.dll File name: Helper.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Leader.exe File name: Leader.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Lardes.exe File name: Lardes.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Milos.exe File name: Milos.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Svtxyse.exe File name: Svtxyse.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Slkyb.exe File name: Slkyb.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Shuokl.exe File name: Shuokl.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Windir%\[Salvitur].pps File name: %Windir%\[Salvitur].pps
Mime Type: unknown/pps
Group: Malware file
%Windir%\[Salvacion].exe File name: %Windir%\[Salvacion].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Windir%\[jesusemais].bat File name: %Windir%\[jesusemais].bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
[RANDOM NUMBER]/config.txt">http://dl.dropbox.com/u/52582137/[REMOVED].txt File name: [RANDOM NUMBER]/config.txt">http://dl.dropbox.com/u/52582137/[REMOVED].txt
Mime Type: unknown/txt
Group: Malware file
camposbijus[REMOVED]/purais/aliont.cdc File name: camposbijus[REMOVED]/purais/aliont.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/eliot.cdc File name: camposbijus[REMOVED]/purais/eliot.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/criosres.cdc File name: camposbijus[REMOVED]/purais/criosres.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/krauser.cdc File name: camposbijus[REMOVED]/purais/krauser.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/siones.cdc File name: camposbijus[REMOVED]/purais/siones.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/helino.cdc File name: camposbijus[REMOVED]/purais/helino.cdc
Mime Type: unknown/cdc
Group: Malware file
camposbijus[REMOVED]/purais/moria.cdc File name: camposbijus[REMOVED]/purais/moria.cdc
Mime Type: unknown/cdc
Group: Malware file

More files
Loading...