Threat Database Trojans Trojan.Banker.TD

Trojan.Banker.TD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,188
Threat Level: 80 % (High)
Infected Computers: 4,281
First Seen: February 18, 2021
Last Seen: July 4, 2026
OS(es) Affected: Windows

The detection of Trojan.Banker.TD indicates that your system has been compromised by a potentially malicious program. This type of threat is generally associated with Trojan-type malware, which can have a range of negative effects on your computer and personal data. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.Banker.TD?

Trojan.Banker.TD is a type of malware that is designed to infiltrate your system and carry out malicious activities without your knowledge or consent. The term "Trojan" refers to the fact that this type of malware often disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. The "Banker" part of the name suggests that this malware may be focused on stealing sensitive financial information, such as login credentials or credit card numbers.

How Trojan.Banker.TD Operates

Once Trojan.Banker.TD has infected your system, it can operate in a variety of ways. It may attempt to communicate with its creators or other malicious programs to receive instructions or transmit stolen data. It can also try to disable security software or other protective measures to maintain its presence on your system. In some cases, this type of malware may also try to spread to other systems or devices, either through network connections or by infecting removable media such as USB drives.

Symptoms of Infection

If your system is infected with Trojan.Banker.TD, you may notice a range of symptoms. These can include unexpected changes to your system settings, unfamiliar programs or icons, and unusual network activity. You may also experience performance issues, such as slow speeds or frequent crashes, as the malware consumes system resources. In some cases, you may receive alerts or warnings from your security software, indicating that it has detected suspicious activity.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Unusual network activity or connectivity issues
  • Performance issues, such as slow speeds or frequent crashes
  • Alerts or warnings from security software

How to Remove Trojan.Banker.TD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be associated with the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Banker.TD from your system requires careful attention to detail and a thorough understanding of the malware's characteristics. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your personal data safe. It is essential to remain vigilant and to regularly scan your system for signs of malware to ensure that you are protected against the latest threats.

Analysis Report

General information

Family Name: Trojan.Banker.TD
Signature status: No Signature

Known Samples

MD5: 987a9a2036ea3b30f01095527dc01216
SHA1: 898a3ef1f75b1c22482753d5f26ee552d3e615f0
File Size: 2.62 MB, 2618880 bytes
MD5: 6382f903d0528ac782111a8a6bbd4cec
SHA1: 89ec2b6ebeae3185a217dbbe5e02afe809414806
SHA256: 4461EBB2D366D0B5F81665980ADDA965503E0F994F043C20D08C66DEBE4D3CE1
File Size: 8.45 MB, 8454656 bytes
MD5: 595f27d939810de0d6de89b642b5c71a
SHA1: 513aca5b67dcfb64a51f8daa8fd11ec1419db532
SHA256: 6F1ED6C3C8217E56EB89B1AD0C9E785D2649E12FCEFFCA3F000A407AABD80F61
File Size: 5.67 MB, 5674886 bytes
MD5: 822062a9864e4693e5748c579bdd70d5
SHA1: aeddef49cfab330c8ef5ee38f2b18308f66fd227
SHA256: A651DBE2E7808D0D0519531E46C4319538389D1C78080215BD6013E6990F2CF2
File Size: 8.95 MB, 8954582 bytes
MD5: 9c20dec56c79f86f75034a9d2d467c4a
SHA1: 90a010ecc07f28a63a8f9f920bc558bed4035eef
SHA256: 7C2C3D8645233EAEE69B6D2090AA08B846AAC77BEB7724F57858B123C2FF641D
File Size: 3.08 MB, 3075751 bytes
Show More
MD5: 80f7ccf65a1043494000811866ac566f
SHA1: b3ce0c3b7d6eb459de7c3e38658bb9bcbd92abf8
SHA256: A9371E172EB46780299AE6E613DB1E041517959E0DDB42C539CC03428839DCFE
File Size: 3.61 MB, 3612672 bytes
MD5: 37456b02caf54d115dc2dbc5971ec70f
SHA1: 26abd6d5169bddf28bf477897042defdb596edd2
SHA256: B8D7D6B4240870E132A93AA022A92AB851D1CA24A3AD085AB69DF3DDCFD58F97
File Size: 6.51 MB, 6511616 bytes
MD5: ba1c281f25f1b8070dc0c6ef5bf04963
SHA1: 9ee9bb50cc531f82305ae2f7da30a921a98257cb
SHA256: 68BA8BB07CD088830AA21A6013A3020950D15FF9C751AF1A0014D2D8FA571FD1
File Size: 7.33 MB, 7326208 bytes
MD5: 8d63db27d214c9466e2c1e3632fe7734
SHA1: 066cbc81b3858e9ac8fc88585edda0281cc1cd3d
SHA256: CA85F6649A865A303C35D4D1623DCDF050EB639A67E5986174153464CD60DD21
File Size: 734.21 KB, 734208 bytes
MD5: e8564cf231d4012063721b2b702bb8ce
SHA1: 08e7858ba69b15c885243ee5cbca36ae37a61376
SHA256: 5350A2C0CF796B3BBCFC5AEBF8672CDACDCEF385C27285CCB405BE0A452DC20B
File Size: 6.66 MB, 6662813 bytes
MD5: 0281efa202162260f412dbdc0ae6b7f4
SHA1: 3b9cfee66a40adf03160f8b46a1ccbbbb65720fc
SHA256: 9E6795041B7C4B90EE7D17C71BA89FDA54BC4C8C3F13CDBF9BEED6E4AE2FFC66
File Size: 9.35 MB, 9353972 bytes
MD5: 895f72e43f5b9ba07edb3e2f12c91d02
SHA1: 0dc1a591396fccaa2b9c6a018709fb1d725e94c6
SHA256: C8E948275F9D2E21764DC937D20D71F0998BFE18CD8FFCE47FF8118697A8EBB0
File Size: 7.68 MB, 7677440 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Synaptics
File Description Synaptics Pointing Device Driver
File Version
  • 1.00
  • 1.0.0.4
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name
  • Project1
  • Synaptics Pointing Device Driver
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • dll
  • HighEntropy
  • No Version Info
  • x86

Block Information

Similar Families

  • FakeAlert.X
  • Kasperagent.A
  • QQPass.AK
  • Trojan.Downloader.Gen.HP
  • Trojan.Downloader.Gen.MD
Show More
  • Woreflint.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcx3373.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\rcxc076.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\rv8fdko.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
c:\users\user\appdata\roaming\winsl\l4\7\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\downloads\._cache_26abd6d5169bddf28bf477897042defdb596edd2_0006511616 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_26abd6d5169bddf28bf477897042defdb596edd2_0006511616 Synchronize,Write Attributes
c:\users\user\downloads\._cache_898a3ef1f75b1c22482753d5f26ee552d3e615f0_0002618880.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_898a3ef1f75b1c22482753d5f26ee552d3e615f0_0002618880.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ]S�r�p��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�������B�O�����x�%���8�5����Bx��� ���\�!IN�sb �!>!wz#@�#��#�O$kF$��$¨%:�%f RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\pc soft\windev\24.0\appli\._cache_898a3ef1f75b1c22482753d5f26ee552d3e615f0_0002618880::last_framework $9 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 *�� xy#kP~�ރ#���� ��^#۴�3}�6Vs}�kP~+�)����1t��4���d#B FF e��1���h�n�}#e��#e�� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �6 �v y� �Z xy �� �a ۀT���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee4Vs}kP~��1.��7 ���ﺃee��� ��1 ��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j8��81��B �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • socket

Shell Command Execution

runas c:\users\user\downloads\._cache_898a3ef1f75b1c22482753d5f26ee552d3e615f0_0002618880.exe
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate
runas c:\users\user\downloads\._cache_26abd6d5169bddf28bf477897042defdb596edd2_0006511616

Related Posts

Trending

Most Viewed

Loading...