Threat Search: 

ThreatExpert's Statistics for Bloodhound.Bancos.1 [Symantec]:

Bloodhound.Bancos.1 [Symantec] is also known as:
Threat AliasNumber of Incidents
Mal/Banspy-F [Sophos]67
HeurEngine.Bancos [PC Tools]36
Mal_Banker [Trend Micro]27
PWS-Banker [McAfee]20
Mal/Banspy-F, Mal/Banspy-I [Sophos]18
Trojan-Banker.Win32.Banker [Ikarus]18
Mal/Generic-A [Sophos]15
New Malware.n [McAfee]14
Trojan-Banker.Win32.Banker.anki [Kaspersky Lab]10
Trojan-Dropper.Delf [Ikarus]9
Generic.Banker.Delf [Ikarus]6
Generic.dx [McAfee]6
Mal/DelpBanc-A [Sophos]6
Mal/Behav-188, Mal/Emogen-T [Sophos]5
Mal/Packer, Mal/Banspy-F, Mal/EncPk-BW [Sophos]4
Packed/Upack [AhnLab]4
PWS-Banker!bgq [McAfee]4
Trojan.Win32.Delf.jwm [Kaspersky Lab]4
Trojan-Banker.Win32.Banker.acjo [Kaspersky Lab]4
Trojan-Banker.Win32.Banker.ammm [Kaspersky Lab]4
Trojan-Dropper.Agent [Ikarus]4
Trojan-Spy.Win32.Bancos [Ikarus]4
TrojanSpy:Win32/Banker [Microsoft]4
Win32/MalPackedB.suspicious [AhnLab]4
Win-Trojan/Bancos.1316352 [AhnLab]4
Backdoor.Hupigon [PC Tools]3
Generic Malware.eb [McAfee]3
Mal/EncPk-AO [Sophos]3
Troj/Bnkmr-Fam [Sophos]3
Trojan-Spy.Banker [Ikarus]3
Gen.Trojan [Ikarus]2
Generic Downloader.x [McAfee]2
Mal/Banc-A [Sophos]2
Mal/Banspy-F, Mal/Banspy-I, Mal/Behav-249 [Sophos]2
Mal/Banspy-F, Mal/EncPk-BW [Sophos]2
Mal/Behav-249 [Sophos]2
Mal/Packer, Mal/Banspy-F, Mal/Behav-249, Mal/EncPk-BW, Mal/Banspy-I, Mal/Behav-188 [Sophos]2
PWS-Banker.gen.bb [McAfee]2
PWS-Banker.gen.i [McAfee]2
Trojan.Delf!sd6 [PC Tools]2
Trojan-Banker.Win32.Banker.aavh [Kaspersky Lab]2
Trojan-Banker.Win32.Banker.akxs [Kaspersky Lab]2
Trojan-Banker.Win32.Banker.amef [Kaspersky Lab]2
Trojan-Downloader.Win32.Agent.qey [Kaspersky Lab]2
Trojan-Spy.Banker.AAF [PC Tools]2
Trojan-Spy.Win32.Banbra [Ikarus]2
Trojan-Spy.Win32.Bancos.BU [Ikarus]2
Trojan-Spy.Win32.Banker [Ikarus]2
Trojan-Spy.Win32.Banker.JU [Ikarus]2
Win-Trojan/Bancos.1627045 [AhnLab]2
Win-Trojan/Banload.460800.C [AhnLab]2
Cryp_PESpin [Trend Micro]1
Generic.dx!ifu [McAfee]1
Mal/Banspy-F, Mal/Bank-A [Sophos]1
Mal/Banspy-I, Mal/Banspy-F, Mal/Behav-249 [Sophos]1
Mal/Banspy-K, Mal/Banspy-F [Sophos]1
Mal/Behav-188 [Sophos]1
Mal/Behav-285 [Sophos]1
Mal/DelpBanc-A, Mal/Banspy-F [Sophos]1
Mal/Packer, Mal/Banspy-F [Sophos]1
Mal/Packer, Mal/Banspy-F, Mal/EncPk-BW, Mal/Banspy-I, Mal/Behav-188 [Sophos]1
Mal/Packer, Mal/Banspy-F, Troj/Bnkmr-Fam [Sophos]1
New Malware.aw [McAfee]1
New Malware.eb [McAfee]1
New Malware.jn [McAfee]1
Packed.Win32.Black.a [Kaspersky Lab]1
Packer.PESpin [Ikarus]1
Packer.RLPack [Ikarus]1
PWS-Banker!bsi [McAfee]1
PWS-Banker!djj [McAfee]1
PWS-Banker!j [McAfee]1
PWS-Banker!m [McAfee]1
PWS-Banker!oe [McAfee]1
PWS-Banker.dr.e [McAfee]1
PWS-Banker.gen.aa [McAfee]1
TROJ_BANKER.NJL [Trend Micro]1
Trojan.ATRAPS [Ikarus]1
Trojan.Win32.Agent.anrh [Kaspersky Lab]1
Trojan.Win32.Agent.btdg [Kaspersky Lab]1
Trojan.Win32.Delf.bji [Kaspersky Lab]1
Trojan.Win32.Delf.frp [Kaspersky Lab]1
Trojan.Win32.Scar.atxh [Kaspersky Lab]1
Trojan-Banker.Win32.Agent.ei [Kaspersky Lab]1
Trojan-Banker.Win32.Banbra [Ikarus]1
Trojan-Banker.Win32.Banbra.gfe [Kaspersky Lab]1
Trojan-Banker.Win32.Banbra.gjt [Kaspersky Lab]1
Trojan-Banker.Win32.Banbra.hj [Ikarus]1
Trojan-Banker.Win32.Banbra.inp [Kaspersky Lab]1
Trojan-Banker.Win32.Banbra.rbz [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.aazl [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.abes [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.acvk [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.aeqq [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.afpu [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.ahdw [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.ahtq [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.akeb [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.alft [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.algx [Kaspersky Lab]1
Trojan-Banker.Win32.Banker.aqoo [Kaspersky Lab]1

Bloodhound.Bancos.1 [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
Brazil198
Germany10
Israel9
Russian Federation6

Bloodhound.Bancos.1 [Symantec] is known to be created as:
%CommonAppData%\updates.exe
%CommonPrograms%\startup\win32sv.exe
%CommonPrograms%\startup\winsv.exe
%CommonPrograms%\startup\winsys32.exe
%ProgramFiles%\internet explorer\6.5\iexplore.exe
%System%\msmsgs.exe
%System%\msnorgl.exe
%System%\raid_n.exe
%System%\reader_sle.exe
%System%\service\services.exe
%System%\svc\svchosts.exe
%System%\temp.exe
%System%\updates.exe
%Windir%\avastss.com
%Windir%\cmsssc.exe
%Windir%\guardiao.exe
%Windir%\msnmsgr.exe
%Windir%\win32sv.exe
%Windir%\winnt.exe
%Windir%\winsv.exe
%Windir%\winsys32.exe
c:\ashdisplay.exe
c:\system\amarelo.exe
c:\system\redst.exe
c:\system\vermelho.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.