Trojan.DownLoader.21677
(TrojanDownloader:Win32/Banload.BEJ, TROJ_BANLOAD.BEJ, Trojan.Downloader.Banload.BEJ, Worm.Win32.Anilogo.b, TR/Dldr.Banload.bej.180, Trojan-Downloader.Win32.Banload.bej, Win32/Banload.BEJ, PWS-Banker.gen.i, Parser error, Downloader.Banload.DQE, TR/Spy.Banker.Gen, Mal_Banker, Downloader.Generic4.GJW, TrojanDownloader:Win32/Small, Possible_Virus)
Added to the Dr.Web virus database:
2007-04-26
Virus description added:
2007-04-27
Virus Type: Malware DownLoader
Affected OS: Win95/98/Me/NT/2000/XP
Size: 200 192 bytes
Packed by: -
Technical Information
During startup this virus creates its copy in system directory Windows (%WINDIR%\System32 for Win 2000\XP and %WINDIR%\System for Win9x\Me) - with such name bios.exe.
For ensuring its loading during each Windows startup registers itself into autoload section of system registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
bios = "C:\WINDOWS\system32\bios.exe"
Opens ports TCP 1033 and UDP 1032 and "listens" Internet.
Downloads and installs onto user’s computer another malicious program, which steals passwords to bank systems - Trojan.PWS.Banker.8838
System recovery information
1. Download from uninfected computer free cure utility Dr.Web CureIt! and record it onto external medium (flash-card or CD-R(W) disk).
2. Disconnect infected computer from local network and/or from Internet.
3. Reboot infected computer in Safe Mode (press F8 during Windows startup).
4. Scan infected computer with Dr.Web CureIt!. Apply “Cure” for all detected objects.