Threat Information for "Trojan.PWS.Banker.4541"

Removal Top

StopSign will automatically remove this infection with a paid membership.

Summary Top
  • Name: Trojan.PWS.Banker.4541
  • Aliases:
  • Date Discovered: 2006-11-15
  • Protection Added: 2006-11-16
Description Top
-- Ease of Removal

1: Uses running processes
2: Consistent file contents
3: Creates new registry entries with consistent data
4: Consistently named

-- Privacy Risks/Security Changes

1: Transmits personal data to remote computers
2: Harvests personal data
3: Harvests saved passwords
4: Logs browsing habits and visited websites
5: Mimics legitimate file names
6: Modifies host files

-- Damage/Intrusion/Annoyance

1: Creates new files

-- Propagation/Saturation

1: Infects from a link in an email
2: Infects from an email attachment
3: Spreads through Peer-2-Peer software
4: Installed by other infections
Technical Details Top
  • Added Directory/File:
    FilePath: %SYSTEMDIR%\sysfldr.tmp
  • Added Directory/File:
    FilePath: %SYSTEMDIR%\system.exe
  • Added Registry Value:
    Key: HKLM\%CURRENTVERSIONREG%\Run Value: HotKeysCmd