Troj/Bancban-F is a Trojan designed to steal bank account information.
When first run, the trojan will drop:
<system32>/securag.dll
<system32>/securag.exe
Which have version information pretending to be a file from Microsoft in the name of:
"Componente do MS-Update"
"Security Agent of MS-Update"
It will also set the following autostart entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Agent = <System32>\securag.exe
The trojan will then display the following error message:
Title: Error message:
'Program Error'
'Raise exception in address EE21FF54.'
'Not possible execute the program. '
After restarting the computer, the trojan will run as a process in the background. It will register itself as a COM server. It may attempt to log keystrokes related to a few websites of banks, including:
'BRADESCO.COM.BR'
'UNIBANCO.COM.BR'
'SANTANDER.COM.BR'