Threat Information for "Trojan.PWS.Banker.4019"

Removal Top

StopSign will automatically remove this infection with a paid membership.

Summary Top
  • Name: Trojan.PWS.Banker.4019
  • Aliases:
  • Date Discovered: 2006-11-03
  • Protection Added: 2006-11-10
Description Top
-- Ease of Removal

1: Uses running processes
2: Consistently named
3: Consistent file contents
4: Creates new registry entries with consistent data

-- Privacy Risks/Security Changes

1: Harvests personal data
2: Captures financial information
3: Mimics legitimate file names
4: Transmits personal data to remote computers

-- Damage/Intrusion/Annoyance

1: Creates new files

-- Propagation/Saturation

1: Infects from a link in an email
2: Infects from an email attachment
Technical Details Top
  • Added Directory/File:
    FilePath: %USERSTARTUP%\msnmsgr.exe
  • Added Directory/File:
    FilePath: %WINDIR%\config\msnmsgr.exe
  • Added Directory/File:
    FilePath: %COMMONSTARTUP%\msnmsgr.exe