Summary

Summary
Action
More Information
| Protection available since | 28 July 2004 08:35:24 (GMT) |
|---|---|
| Last updated | 17 November 2005 13:24:08 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Change any data that may have become compromised.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Agent = <System32>\securag.exe
and delete it if it exists.
Close the registry editor.
More Information
Troj/Bancban-F is a Trojan designed to steal bank account information.
When first run, the trojan will drop:
<system32>/securag.dll
<system32>/securag.exe
Which have version information pretending to be a file from Microsoft in the name of:
"Componente do MS-Update"
"Security Agent of MS-Update"
It will also set the following autostart entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Agent = <System32>\securag.exe
The trojan will then display the following error message:
Title: Error message:
'Program Error'
'Raise exception in address EE21FF54.'
'Not possible execute the program. '
After restarting the computer, the trojan will run as a process in the background. It will register itself as a COM server. It may attempt to log keystrokes related to a few websites of banks, including:
'BRADESCO.COM.BR'
'UNIBANCO.COM.BR'
'SANTANDER.COM.BR'
