Home Malware Programs Trojans TrojanSpy:Win32/Bancos.DJ

TrojanSpy:Win32/Bancos.DJ

Posted: August 5, 2011

TrojanSpy:Win32/Bancos.DJ is a hazardous Trojan infection designed for log keystroke users to type on the keyboard. TrojanSpy:Win32/Bancos.DJ can log very detailed information such user's account information, passwords, websites visited, credit cards numbers, even take screenshot of users activity and record online chatting. TrojanSpy:Win32/Bancos.DJ invades your privacy and compromises your security. TrojanSpy:Win32/Bancos.DJ adds malicious elements to legitimate applications and changes their settings in order to corrupt files opened or created with these applications. TrojanSpy:Win32/Bancos.DJ is a serious risk for the corrupted PC system and needs to be removed immediately after detection.

Aliases

TrojanSpyWin32BancosDJ

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



(Default) = "%AppData%\Firewall.exe" File name: (Default) = "%AppData%\Firewall.exe"
Mime Type: unknown/exe"
msngrsw = "%System%\msngrsw.exe" File name: msngrsw = "%System%\msngrsw.exe"
Mime Type: unknown/exe"
taskmgra = "%System%\taskmde.youtube.superpop.http.www.youtube.com" File name: taskmgra = "%System%\taskmde.youtube.superpop.http.www.youtube.com"
Mime Type: unknown/com"
explorer = "%System%\internetx.com" File name: explorer = "%System%\internetx.com"
Mime Type: unknown/com"
%UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.lnk File name: %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Desktop\TrojanSpy:Win32/Bancos.DJ.lnk File name: %UserProfile%\Desktop\TrojanSpy:Win32/Bancos.DJ.lnk
File type: Shortcut
Mime Type: unknown/lnk
%Program Files%\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.exe File name: %Program Files%\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.exe
File type: Executable File
Mime Type: unknown/exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanSpy:Win32/Bancos.DJ.lnk File name: %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanSpy:Win32/Bancos.DJ.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Registration.lnk File name: %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Registration.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Help.lnk File name: %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Help.lnk
File type: Shortcut
Mime Type: unknown/lnk

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BORD_007\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BORD_007HKEY_CURRENT_USER\Firewall.exeHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\AttachmentsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
Loading...