Home Malware Programs Trojans Trojanspy.Win32.Banker

Trojanspy.Win32.Banker

Posted: March 28, 2006

Threat Metric

Ranking: 18,977
Threat Level: 9/10
Infected PCs: 925
First Seen: July 24, 2009
Last Seen: December 27, 2024
OS(es) Affected: Windows

This keylogger is designed to steal financial information, such as financial documents, passwords, etc. It scans the keylog, retrieves the valuable information and sends it to hacker. This keylogger belongs to a large money-stealing family of keyloggers, designed for illegal financial activity. It may also include a 'backdoor' function.

Trojanspy.Win32.Banker

Aliases

Trj/Banker.ITS [Panda]PSW.Banker.CXM [AVG]W32/Banker.TOA!tr [Fortinet]Troj/Bancb-Fam [Sophos]Heuristic.LooksLike.Win32.Suspicious.F [McAfee-GW-Edition]TrojWare.Win32.Spy.Banker.Gen [Comodo]Trojan-Banker.Win32.Banker.add [Kaspersky]Win32.Banker.add [eSafe]Win32:Banker-AKX [Trj] [Avast]W32/Banker.BWD [F-Prot]Artemis!2E40F0BD1D17 [McAfee]Win32.TrojanSpy.Banker.abg.d [CAT-QuickHeal]PSW.Banker6.ETM [AVG]W32/Banker.42FF!tr [Fortinet]Trojan/Win32.Gen [AhnLab-V3]
More aliases (793)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



wmiprevse.exe File name: wmiprevse.exe
Size: 86.01 KB (86016 bytes)
MD5: 9f188cb4273bfec742a29d995ce3d72c
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
winhlpj.exe File name: winhlpj.exe
Size: 870.91 KB (870912 bytes)
MD5: 1d841b8f7b37502b1eedbfea70479f6a
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 5, 2010
winhlpf.exe File name: winhlpf.exe
Size: 488.96 KB (488960 bytes)
MD5: 0156302f88e05dbcebc67c932a529ddf
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 5, 2010
qwesddddd.dll File name: qwesddddd.dll
Size: 45.34 KB (45348 bytes)
MD5: 66ce4952455eb6fc2129d0e2aa1ccd00
Detection count: 92
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
imglog.exe File name: imglog.exe
Size: 1.21 MB (1212351 bytes)
MD5: 0cbec6f63d85d8d60dbaa09d07786022
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
liel.exe File name: liel.exe
Size: 494.59 KB (494592 bytes)
MD5: f6f64fbff854fe2c04432ddcb9e8cbf6
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 189.46 KB (189460 bytes)
MD5: 6ff126fbfba2d6cdac39a1122c4b27f7
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: November 20, 2018
imola.exe File name: imola.exe
Size: 606.72 KB (606720 bytes)
MD5: bdcdf49382a9d6852726ea7d26955927
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 3, 2010
Windows32.exe File name: Windows32.exe
Size: 3.99 MB (3995136 bytes)
MD5: b7ea7d0e80510679054de0ebdb72ebef
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
system.exe File name: system.exe
Size: 3.72 MB (3727360 bytes)
MD5: fecf1bf998b0e6b5331c2cc2f7c0b405
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 1, 2010
temp01.exe File name: temp01.exe
Size: 2.46 MB (2466677 bytes)
MD5: ae8a862aae6289c2d0362c9942d87242
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 28, 2010
winnt2.exe File name: winnt2.exe
Size: 2.24 MB (2246656 bytes)
MD5: 27459954439b12bbbbf58cd25dad7161
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Explorer.exe File name: Explorer.exe
Size: 621.56 KB (621568 bytes)
MD5: e34a0399592df0a799ac6e76788e83bf
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%APPDATA%\crss.exe File name: crss.exe
Size: 90.11 KB (90112 bytes)
MD5: 7c6ef02afe5e2723c945a821c933531c
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 14, 2017
RunDLL31.exe File name: RunDLL31.exe
Size: 4.15 MB (4152320 bytes)
MD5: 18c432cdbfe28558bbba4e834bef6e16
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
krn4.exe File name: krn4.exe
Size: 4.79 MB (4798976 bytes)
MD5: 997870a187d84d65609d683c9952728a
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%WINDIR%\svchosts.scr File name: svchosts.scr
Size: 819.71 KB (819712 bytes)
MD5: 2e40f0bd1d17ba2622dad3098a2c594a
Detection count: 5
Mime Type: unknown/scr
Path: %WINDIR%
Group: Malware file
Last Updated: October 17, 2012

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\crss.exe%USERPROFILE%\internet.dll
Loading...