1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Banload.BBX

Name : Banload.BBX
Size:10,804 bytes
Category:Malware
Type:Trojan-Downloader
Platform:W32
Origin:BRAZIL
Date of Discovery:August 04, 2006

Summary

Banload.BBX connects to the internet and downloads other members of the Banker and Banload family. It arrives on the system using the filename, HUMORTADELA.exe. The downloaded files are already detected as Trojan-Spy.Win32.Bancos.uy and Trojan-Downloader.Win32.Banload.bby.

Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Additional Details

Banload.BBX downloads other members of the Banker and Banload family from the internet.
It arrives on the system with the filename HUMORTADELA.exe.
Upon execution, it connects to the following sites:
  •  http://www.guitarparts.com/zero/[REMOVED].exe
  • http://www.guitarparts.com/zero/[REMOVED].exe

And saves these files to the following hard-coded paths in the user's system:
  •   c:\windows\system32\svhootss.exe
  • c:\windows\system32\Msn.exe

The said files are already detected as Trojan-Spy.Win32.Bancos.uy and Trojan-Downloader.Win32.Banload.bby respectively.
As a stealth mechanism, it displays the following fake error message to fool the users into believeing that the malware did not run on their system.

Detection

F-Secure Anti-Virus detects this malware with the following updates:

[FSAV_Database_Version]

Version = 2006-08-04_02.