Sophos

Troj/Bancban-F

Aliases
  • PWS-Bancban.gen.b
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 28 July 2004 08:35:24 (GMT)
Last updated 17 November 2005 13:24:08 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

Please follow the instructions for removing Trojans.

Change any data that may have become compromised.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Agent = <System32>\securag.exe

and delete it if it exists.

Close the registry editor.

More Information

Troj/Bancban-F is a Trojan designed to steal bank account information.

When first run, the trojan will drop:
<system32>/securag.dll
<system32>/securag.exe
Which have version information pretending to be a file from Microsoft in the name of:
"Componente do MS-Update"
"Security Agent of MS-Update"

It will also set the following autostart entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Agent = <System32>\securag.exe

The trojan will then display the following error message:
Title: Error message:
'Program Error'
'Raise exception in address EE21FF54.'
'Not possible execute the program. '

After restarting the computer, the trojan will run as a process in the background. It will register itself as a COM server. It may attempt to log keystrokes related to a few websites of banks, including:
'BRADESCO.COM.BR'
'UNIBANCO.COM.BR'
'SANTANDER.COM.BR'

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer