Threat Database Trojans TrojanSpy: Win32/Bancos.DJ

TrojanSpy: Win32/Bancos.DJ

By SpideyMan in Trojans

TrojanSpy:Win32/Bancos.DJ is a mischievous Trojan that opens up firewalls and gathers its victim's personal information. Once TrojanSpy: Win32/Bancos.DJ completely installs onto an affected computer system, it will hide its infected files deeply in the PC system, and the targeted user won't be able to know about the changes of the computer system. It is highly recommended to uninstall TrojanSpy:Win32/Bancos.DJ instantly upon detection.

File System Details

TrojanSpy: Win32/Bancos.DJ may create the following file(s):
# File Name Detections
1. %Program Files%\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.exe
2. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanSpy:Win32/Bancos.DJ.lnk
3. explorer = "%System%\internetx.com"
4. (Default) = "%AppData%\Firewall.exe"
5. %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Registration.lnk
6. %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\TrojanSpy:Win32/Bancos.DJ.lnk
7. msngrsw = "%System%\msngrsw.exe"
8. %UserProfile%\Start Menu\TrojanSpy:Win32/Bancos.DJ\Help.lnk
9. %UserProfile%\Desktop\TrojanSpy:Win32/Bancos.DJ.lnk
10. taskmgra = "%System%\taskmde.youtube.superpop.http.www.youtube.com"

Registry Details

TrojanSpy: Win32/Bancos.DJ may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Firewall.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BORD_007\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007\Enum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BORD_007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bord_007\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bord_007\Security

Trending

Most Viewed

Loading...