Sophos

Troj/Bancban-NN

Aliases
  • Trojan-Spy.Win32.Banker.apk
  • PWS-Banker.gen.bb
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2006 (4.05)
Protection available since 10 January 2006 06:03:25 (GMT)
Last updated 3 April 2006 14:54:35 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancban-NN is a Trojan for the Windows platform.

Troj/Bancban-NN includes functionality to:

- access the internet and communicate with a remote server via HTTP
- send notification messages to remote locations

When first run Troj/Bancban-NN copies itself to <System>\dllhostup.exe and creates the following files:

<Downloaded Program Files>\Bb.gpc
<Downloaded Program Files>\GbPluginABN.inf
<Downloaded Program Files>\GbPluginBb.inf
<Downloaded Program Files>\GbPluginuni.inf
<Downloaded Program Files>\abn.gpc
<Downloaded Program Files>\gbieh.gmd
<Downloaded Program Files>\gbiehabn.gmd
<Downloaded Program Files>\gbpdist.dll
<Downloaded Program Files>\uni.gpc

The following registry entry is created to run dllhostup.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Update
<System>\dllhostup.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer