Unsolved
This post is more than 5 years old
4 Apprentice
•
20.5K Posts
0
8611
April 1st, 2008 11:00
New Banking Trojan
From F-Secure:
Unusual Banking Trojan Found Today
This new banking trojan was found today from a drive-by-download site. We've added detection for it as Win32.Pril.A
It not only infects the MBR of the machine, but also reflashes the boot code in the Flash BIOS, making disinfection problematic.
Once an infected machine is online, the trojan monitors the users actions, waiting him to go to go to one of several hundred online banks, located all over the world.
More with screenshot here:
http://www.f-secure.com/weblog/archives/00001411.html
No Events found!


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
April 1st, 2008 12:00
Pril.A ...
as in A.Pril Fool's
Bugbatter
4 Apprentice
•
20.5K Posts
0
April 1st, 2008 14:00
beversoll
2 Intern
•
301 Posts
0
April 1st, 2008 20:00
Wow. I am going to try to get my pc infected tonight.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
April 1st, 2008 23:00
I'm a tad slow- twas only when I reached the part about:
"Normal banking trojans would insert extra transactions or change the deposit account numbers on-the-fly. However, Win32.Pril.A doesn't withdraw money from you - it actually inserts money TO your account."
... that I twigged. :smileyvery-happy: