Additional Details
Upon execution, Bancos.VE displays the following fake error message:
It will then drop a copy of itself into the System Directory as Tasklist32.exe:
- %systemdir%\tasklist32.exe
Note: %systemdir% by default is C:\Windows\System32.
It also creates the following registry value for its auto-start mechanism:
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TaskList = "%systemdir%\tasklist32.exe"
This malware monitors users' visited URLs. When specific URLs are viewed by a user, it will log all keyboard strokes.
Below are the URLs monitored by this trojan:
- bankline.itau.com.br
- https://www2.bancobrasil.com.br/aapf/saldos/006.jsp?codT=0
- https://www2.bancosbrasil.com.br/aapff/aaii/principal
- www2.bancobrasil.com.br
Bancos.VE sends the gathered information to a Brazilian e-mail address.
Detection
F-Secure Anti-Virus detects this malware with the following updates:
[FSAV_Database_Version]
Version = 2006-08-07_01.
F-Secure Corporation