Threat Database Stealers Infostealer.Banker.E

Infostealer.Banker.E

By LoneStar in Stealers

Infostealer.Banker.E is a banking Trojan that is able to steal a PC user's confidential information, specifically user account and banking details from the corrupted machine. Once Infostealer.Banker.E is installed, it creates its startup registry entry to start every time you boot up your computer. Infostealer.Banker.E also drops corrupt files and creates registry entries to destroy your PC system. Infostealer.Banker.E may create some files to gather the stolen information and to exchange commands with the remote server. Infostealer.Banker.E also has back door capabilities and contacts a remote host on TCP port 80. Infostealer.Banker.E receives commands from the remote attacker and can accomplish malicious actions. Delete Infostealer.Banker.E immediately after detection to avoid system damage.

File System Details

Infostealer.Banker.E may create the following file(s):
# File Name Detections
1. %System%\tns1.dll
2. %System%\cookie1.dat
3. %System%\te.dat
4. %System%\boa1.dat
5. %System%\di1.gif
6. %System%\conf1.dat
7. %System%\ps1.dat
8. %System%\cs.dat
9. %System%\alog.txt
10. %System%\conf.dat
11. %System%\rc.dat
12. %System%\bb1.dat
13. %System%\cmds.txt
14. %System%\dr1.gif

Registry Details

Infostealer.Banker.E may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft\"P" = "[HEX VALUES]"
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft\"1" = "[ENCRYPTED CHARACTERS]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{775B738B-4540-4b16-A1DA-932C402FD8F7}
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLISD\{775B738B-4540-4b16-A1DA-932C402FD8F7}

Trending

Most Viewed

Loading...