









 |
W32/Bandra.DO Trojan
| Name |
W32/Bandra.DO Trojan |
| Aliases |
TSPY_BANKER.AHL |
| Discovered on |
October 16, 2005 |
Virus Information - W32/Bandra.DO Trojan:
W32/Bandra.DO is a trojan. The trojan will infect Windows systems and spreads through email.
This trojan is downloaded by W32/Dabora.A Worm.
Upon execution, the trojan copies itself as iexplore.exe in the Windows folder.
It modifies the Windows registry at the following locations to load itself during next startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In order to steal the credit card information, the trojan bluffs the user by displaying a fake login window requesting the user for his/her username, password and other secured information.
Once the user enters these information, it sends the entered information to the following website;
http://[blocked]/infos.txt

|