Sophos

Sophos blogs

Troj/Banker-HS

Aliases
  • Trojan-Spy.Win32.Banker.ri
  • PWSteal.Bancos
  • W32/Bancos.AIQ
  • W32/Banker.CNE
  • PWS-Banker.gen.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 30 November 2005 14:10:55 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Banker-HS is a password-stealing Trojan that targets users of Brazilian banking websites.

Troj/Banker-HS attempts to log keypresses entered into specific websites. The Trojan may display fake user interfaces in order to pursuade the user to enter confidential details such as account number, login name, password and PIN. Stolen information is sent by email to a remote user.

Troj/Banker-HS comprises of the installer and main executable components.

When Troj/Banker-HS is installed the following files are created:

<Temp>\ci0-temp\Ferdg.set
<Temp>\gert0.dll
<Windows>\ie\winB_.exe

where gert0.dll is a part of the installer, winB_.exe is the main executable and Ferdg.set is a customized setup script that is not malicious on its own and may safely be deleted.

The following registry entry is created to run winB_.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
getwin
<Windows>\IE\winB_.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer