Threat Database Trojans TrojanDownloader:Win32/Banload.ARZ

TrojanDownloader:Win32/Banload.ARZ

By Domesticus in Trojans

TrojanDownloader:Win32/Banload.ARZ is a Trojan that drops other files on the affected computer. If a PC user has a Battle.net account, TrojanDownloader:Win32/Banload.ARZ deletes an account information by deleting the data in the registry subkey or may make it not work as expected. Once installed, TrojanDownloader:Win32/Banload.ARZ makes system changes by downloading malevolent files and modifying the Windows Registry. TrojanDownloader:Win32/Banload.ARZ creates the registry entry so that the dropped file can automatically load whenever you start Windows. TrojanDownloader:Win32/Banload.ARZ checks if the compromised PC is connected to the web. If so, TrojanDownloader:Win32/Banload.ARZ connects to the particular servers to drop a specific file. TrojanDownloader:Win32/Banload.ARZ permits processes to run with elevated privileges. TrojanDownloader:Win32/Banload.ARZ modifies the registry entry so that any elevated action is fulfilled without forcing the PC user.

File System Details

TrojanDownloader:Win32/Banload.ARZ may create the following file(s):
# File Name Detections
1. %TEMP%\SMSvcHost.exe

Registry Details

TrojanDownloader:Win32/Banload.ARZ may create the following registry entry or registry entries:
HKEY_CURRENT_USER\SOFTWARE\Blizzard Entertainment\Battle.net\Identity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System "ConsentPromptBehaviorAdmin" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AhnLab V3Lite Update Process" "SMSvcHost.exe"

Trending

Most Viewed

Loading...