Threat Database Trojans Trojan:BAT/Bancos.B

Trojan:BAT/Bancos.B

By Domesticus in Trojans

Trojan:BAT/Bancos.B is a Trojan that modifies a targeted PC's security settings by blocking alerts in Windows Security Center from emerging so that the computer is not announced if automatic Windows updates, antivirus application, or Windows Firewall are disabled. While being executed, Trojan:BAT/Bancos.B makes system changes by downloading harmful files and modifying the Windows Registry. Trojan:BAT/Bancos.B creates the registry entry so that it can start automatically whenever the computer boots up Windows. Trojan:BAT/Bancos.B may be installed on the victimized machine by other malware infections. Trojan:BAT/Bancos.B also disables System Restore in the affected computer system. Trojan:BAT/Bancos.B also disables User Account Control (UAC). Trojan:BAT/Bancos.B steals the affected computer owner's confidential information and computer data and transfers his/her Windows user name and computer name to a distant server.

SpyHunter Detects & Remove Trojan:BAT/Bancos.B

File System Details

Trojan:BAT/Bancos.B may create the following file(s):
# File Name MD5 Detections
1. ctfmon.exe
2. crash.bat
3. video-oral-de-paris-hilton-com-seu-atual-namorado-_ant_com_end.bat.SBOX 5ff82c9ccad37cc0a76bd8c0dcbc7fa1 0

Registry Details

Trojan:BAT/Bancos.B may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "FirewallDisableNotify" = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings "DisableSR" = "1"
HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "UpdatesDisableNotify" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "EnableLUA" = "0>"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit" = "C:\Windows\system32\userinit.exe,%temp%\ctfmon.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center "AntiVirusDisableNotify" = "1"

Trending

Most Viewed

Loading...