Threat Description

Bancos.VE

Details

Aliases:Bancos.VE
Category:Malware
Type:Trojan-Spy
Platform:W32

Summary



Bancos.VE is a password stealing trojan specifically designed for stealing Bank Information from users of Brazilian Banks.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Upon execution, Bancos.VE displays the following fake error message:

It will then drop a copy of itself into the System Directory as Tasklist32.exe:

  • %systemdir%\tasklist32.exe

Note: %systemdir% by default is C:\Windows\System32.

It also creates the following registry value for its auto-start mechanism:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

TaskList = "%systemdir%\tasklist32.exe"

This malware monitors users' visited URLs. When specific URLs are viewed by a user, it will log all keyboard strokes.

Below are the URLs monitored by this trojan:

  • bankline.itau.com.br
  • https://www2.bancobrasil.com.br/aapf/saldos/006.jsp?codT=0
  • https://www2.bancosbrasil.com.br/aapff/aaii/principal
  • www2.bancobrasil.com.br

Bancos.VE sends the gathered information to a Brazilian e-mail address.



Detection


F-Secure Anti-Virus detects this malware with the following updates:
Detection Type: PC
Database: 2006-08-07_01




SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More