1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Bancos.VE

Type:Spy, Trojan
Category:Trojan
Date of Discovery:August 07, 2006

Summary

Bancos.VE is a password stealing trojan specifically designed for stealing Bank Information from users of Brazilian Banks.

Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Additional Details

Upon execution, Bancos.VE displays the following fake error message:



It will then drop a copy of itself into the System Directory as Tasklist32.exe:
  • %systemdir%\tasklist32.exe
Note: %systemdir% by default is C:\Windows\System32.

It also creates the following registry value for its auto-start mechanism:
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TaskList = "%systemdir%\tasklist32.exe"

This malware monitors users' visited URLs. When specific URLs are viewed by a user, it will log all keyboard strokes.

Below are the URLs monitored by this trojan:
  • bankline.itau.com.br
  • https://www2.bancobrasil.com.br/aapf/saldos/006.jsp?codT=0
  • https://www2.bancosbrasil.com.br/aapff/aaii/principal
  • www2.bancobrasil.com.br
Bancos.VE sends the gathered information to a Brazilian e-mail address. Detection F-Secure Anti-Virus detects this malware with the following updates:


[FSAV_Database_Version]
Version = 2006-08-07_01.


F-Secure Corporation