Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Bancos.VE


Discovered:
Aliases:


August 07, 2006
Bancos.VE

Malware
Trojan-Spy
W32

Summary

Bancos.VE is a password stealing trojan specifically designed for stealing Bank Information from users of Brazilian Banks.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

Upon execution, Bancos.VE displays the following fake error message:

It will then drop a copy of itself into the System Directory as Tasklist32.exe:

  • %systemdir%\tasklist32.exe

Note: %systemdir% by default is C:\Windows\System32.

It also creates the following registry value for its auto-start mechanism:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

TaskList = "%systemdir%\tasklist32.exe"

This malware monitors users' visited URLs. When specific URLs are viewed by a user, it will log all keyboard strokes.

Below are the URLs monitored by this trojan:

  • bankline.itau.com.br
  • https://www2.bancobrasil.com.br/aapf/saldos/006.jsp?codT=0
  • https://www2.bancosbrasil.com.br/aapff/aaii/principal
  • www2.bancobrasil.com.br

Bancos.VE sends the gathered information to a Brazilian e-mail address.



Detection

F-Secure Anti-Virus detects this malware with the following updates:

Detection Type: PC
Database: 2006-08-07_01





Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.