Remove Trojan.Bankpatch.D
Posted on: April 14th, 2009
| Discovered: | April 12, 2009 |
| Updated: |
April 12, 2009 10:50:33 AM |
| Type: |
Trojan |
| Systems Affected: |
Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 |
| Recommended Action: |
|
best peforming remover of Trojan.Bankpatch.D.. You will see the download link on their website, once installed it will perform |
| Technical Details: |
|
When the Trojan is executed, it copies itself as the following files: * %System%\pwrcode.dat Next, it creates the following files: * %System%\sysk.tmp (Copy of kernel32.dll) The Trojan then injects code into the following files: * %System%\kernel32.dll Note:The modified files are detected as Trojan.Bankpatch.C!inf and may It also creates the following files: * %System%\nsysk.ini (Trojan.Bankpatch.C!inf) The Trojan injects different code in to each infected .dll file. Next, the Trojan modifies the following Windows APIs for %System% * CreateFileW The Trojan modifies the following Windows APIs for %System%\ * HttpSendrequestA It also modifies the following Windows APIs for %System%\powrprof.dll: * SetSuspendState The threat creates the following file, that contains an encrypted version of Next, it creates the following registry entries in order to save its configuration: * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current It may also create the following registry subkeys in order to save configuration * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current The Trojan attempts to run the following command in order to uninstall JAVA It attempts to restart the computer after a certain period of time in order to When the the computer restarts, the threat monitors the browser for certain It then gathers the information and sends it to the following remote Web server: The Trojan then attempts to retrieve and verify the home page of google.com It then sends the following request to the remote server: The Trojan attempts to steal cookie files that contain the following strings in * 2o7 It then stores the gathered cookie files in the following location: The threat creates the following folder in order to store configuration files from It also attempts to log keystrokes and store them in the following location: The Trojan searches for the following browser plugins when Internet Explorer * JAVA It creates the following registry subkeys in order to download more components * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current It downloads the following files and registers them as Browser Helper Objects * %System%\[RANDOM CHARACTERS].dll It may also download the following file, which is an update of the Trojan: The Trojan may decrypt the original %System%\ldshyf1.old file in order to It may then run the file from the following location: . |
| Action Steps: |
FREE SCAN: NoAdware can remove Trojan.Bankpatch.D. Click the link below for your free download & scan your PC now. MANUAL REMOVAL: Please click here for manual removal instructions. |
In order to remove Remove Trojan.Bankpatch.D you need to 
