Threat Search: 

ThreatExpert's Statistics for Trojan-Banker.Win32.Banker.etk [Kaspersky Lab]:

Trojan-Banker.Win32.Banker.etk [Kaspersky Lab] is also known as:
Threat AliasNumber of Incidents
Trojan.Crypt [Ikarus]55
Trojan-Banker.Win32.Banker [Ikarus]28
Mal/Generic-A [Sophos]20
TrojanSpy:Win32/Bancos.gen!B [Microsoft]17
Mal/DelpBanc-A, Mal/Banspy-F, Mal/Banspy-I [Sophos]11
Trojan-Spy.Banker [Ikarus]11
TrojanSpy:Win32/Bancos.gen!C [Microsoft]11
Mal/DelpBanc-A, Mal/Banspy-F, Mal/Behav-249, Mal/Banspy-I [Sophos]10
Mal/Banspy-F, Mal/Behav-249, Mal/Banspy-I [Sophos]9
Mal/Banker-E [Sophos]8
Spyware.Perfect [Symantec]8
Trojan-Spy.Win32.Banker.JU [Ikarus]8
Packed/Upack [AhnLab]6
Infostealer.Bancos [Symantec]5
Mal/Behav-249, Mal/Banspy-I [Sophos]5
Trojan-Proxy.Win32.Delf.av [Ikarus]5
Generic.Banker.Delf [Ikarus]4
Mal/DelpBanc-A, Mal/Packer, Mal/EncPk-BW, Mal/Banspy-I [Sophos]4
TrojanDownloader:Win32/Banload.gen!N [Microsoft]4
Trojan-Spy.Win32.Bancos [Ikarus]4
Win-Trojan/Banker.2779648 [AhnLab]4
Generic.Generic.Banker.Delf [Ikarus]3
Infostealer.Bancos!gen [Symantec]3
Mal/DelpBanc-A, Mal/Packer, Mal/Behav-249, Mal/Banspy-I [Sophos]3
New Malware.aj [McAfee]3
Trojan-Downloader.Win32.Banload [Ikarus]3
TrojanSpy:Win32/Banker [Microsoft]3
Mal/Banspy-F, Mal/Behav-249, Mal/Behav-248, Mal/Banspy-I, Mal/Banspy-G [Sophos]2
Mal/DelpBanc-A, Mal/Behav-249, Mal/Banspy-I [Sophos]2
PWS-Banker.gen.ba [McAfee]2
Trojan Horse [Symantec]2
Trojan-Spy.Banker!sd5 [PC Tools]2
Virus.Win32.Banker.CYL [Ikarus]2
Win-Trojan/Banker.3720192.B [AhnLab]2
Win-Trojan/Banker.3793408.D [AhnLab]2
Downloader [Symantec]1
Dropper/Banker.4390400 [AhnLab]1
Mal/Banker-B, Mal/Banspy-F, Mal/Behav-248, Mal/Banspy-I, Mal/Banspy-G, Troj/Bnkmr-Fam [Sophos]1
Mal/Banspy-F, Mal/Behav-248, Mal/Banspy-I, Mal/Banspy-G, Troj/Bnkmr-Fam [Sophos]1
Mal/Banspy-G [Sophos]1
Mal/Behav-103, Mal/Behav-043 [Sophos]1
Mal/Behav-180 [Sophos]1
Mal/Behav-248 [Sophos]1
Mal/Behav-248, Mal/Banspy-G [Sophos]1
Mal/DelpBanc-A, Mal/Banspy-F, Mal/Banspy-I, Mal/Behav-103, Mal/Behav-043 [Sophos]1
Mal/DelpBanc-A, Mal/Banspy-I [Sophos]1
Mal/DelpBanc-A, Mal/EncPk-BU, Mal/Packer, Mal/Behav-249, Mal/Banspy-I, Mal/EncPk-BA [Sophos]1
Mal/EncPk-DM [Sophos]1
Mal_Banker [Trend Micro]1
Packed.Generic.138 [Symantec]1
PWS-Banker.gen.bc [McAfee]1
Trojan.Generic [PC Tools]1
Trojan.PWS.Banker.ACUD [PC Tools]1
Trojan:Win32/Esimtipy [Microsoft]1
Trojan-Downloader.Win32.Dluca [Ikarus]1
TrojanDownloader:Win32/Banload.gen!B [Microsoft]1
Trojan-Dropper.Agent [Ikarus]1
TrojanSpy.Banker.AQYF [PC Tools]1
Trojan-Spy.Win32.Banker.ark [Ikarus]1
Trojan-Spy.Win32.Banker.bbh [Ikarus]1
Trojan-Spy.Win32.Banker.cow [Ikarus]1
Trojan-Spy.Win32.Banker.etk [Ikarus]1
Trojan-Spy.Win32.Banker.USY [Ikarus]1
TrojanSpy:Win32/Bancos.gen!A [Microsoft]1
TrojanSpy:Win32/Bancos.OT [Microsoft]1
TSPY_BANCOS.AKD [Trend Micro]1
Win32/ExprPacked.suspicious [AhnLab]1
Win32/MalPackedB.suspicious [AhnLab]1
Win-Trojan/Banker.3415090 [AhnLab]1
Win-Trojan/Banker.3793408.C [AhnLab]1
Win-Trojan/Banker.3909632.E [AhnLab]1
Win-Trojan/Xema.variant [AhnLab]1

Trojan-Banker.Win32.Banker.etk [Kaspersky Lab] has the following possible country of origin:
OriginNumber of Incidents
Brazil156

Trojan-Banker.Win32.Banker.etk [Kaspersky Lab] is known to be created as:
%CommonPrograms%\startup\lsass.exe
%CommonPrograms%\startup\windowsupdate.exe
%System%\avg.exe
%System%\future.exe
%System%\informativos.exe
%System%\microsoft\security.exe
%System%\msngr.exe
%System%\svchosste.exe
%System%\svchosts.exe
%Windir%\system.exe
%Windir%\system\wini.exe
Notes:
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.