Threat Database Trojans Trojan-Banker.Win32.Banker.auzi

Trojan-Banker.Win32.Banker.auzi

By ESGI Advisor in Trojans

Trojan-Banker.Win32.Banker.auzi is a malignant trojan infection that may control your search requests and steal your passwords when you visit the websites of major banks. Trojan-Banker.Win32.Banker.auzi Trojan downloads other infected applications from the web and starts them on the targeted user's PC. Trojan-Banker.Win32.Banker.auzi is able to communicate with a remote SMTP server to send out email messages with the built-in SMTP client engine. It is important to remove Banker.Win32.Banker.auzi as quickly as possible to avoid loss of data and infection of files on the computer system.

File System Details

Trojan-Banker.Win32.Banker.auzi may create the following file(s):
# File Name Detections
1. %System%\islupj.exe
2. %System%\islupc.exe
3. c:\wabs.exe
4. %System%\islup.exe
5. c:\%ComputerName%.txt
6. c:\tyu.txt

Registry Details

Trojan-Banker.Win32.Banker.auzi may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer
HKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft\Rpc\UuidTemporaryData
HKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft\Rpc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client\SuperSocketNetLib
HKEY_LOCAL_MACHINE\SOFTWARE\Description
HKEY_CURRENT_USER\Software\Microsoft\uxPtgYTx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client\SuperSocketNetLib\LastConnect
HKEY_LOCAL_MACHINE\SOFTWARE\Description\Microsoft

Trending

Most Viewed

Loading...