Skip to main content
Skip to main content
Microsoft Security Intelligence
14 entries found.
Updated on May 27, 2011

Win32/Bamital is a family of malware that intercepts web browser traffic and prevents access to certain security-related websites by modifying the Hosts file. Bamital variants may also modify certain legitimate Windows files in order to execute their payload.

In the wild, the Bamital family has been used to perpetrate click-fraud.

Alert level: severe
Updated on Apr 09, 2010
Trojan:Win32/Bamital.F is a component of the Win32/Bamital family. It is used by variants of TrojanDropper:Win32/Bamital to execute code previously saved in specific registry keys. The code is intended to monitor and modify Web search queries and displays advertisements. It affects users of Internet Explorer, Opera, and Firefox browsers.
Alert level: severe
Updated on Apr 19, 2010
Trojan:Win32/Bamital.E is a component of the Win32/Bamital family. It is dropped by variants of TrojanDropper:Win32/Bamital to execute code previously saved in specific registry keys. The code is intended to monitor and modify Web search queries and display advertisements. It affects users of Internet Explorer, Opera, and Firefox browsers.
Alert level: severe
Updated on Apr 20, 2010
TrojanDropper:Win32/Bamital.A is a component of Win32/Bamital - a family of trojans intended to monitor and modify Web search queries and display advertisements. It affects users of Internet Explorer, Opera, and Firefox browsers.
Alert level: severe
Updated on Jul 08, 2010
TrojanDropper:Win32/Bamital.G is a detection for trojans that monitor and modify Web search queries and display advertisements, as well as modifying system DLLs such as "user32.dll".
Alert level: severe
Updated on Sep 01, 2010
Trojan:Win32/Bamital is a detection for a trojan that intercepts web browser traffic and redirects web search queries.
Alert level: severe
Updated on Oct 14, 2010
Trojan:Win32/Bamital.G is a trojan component that executes a payload component installed by TrojanDropper:Win32/Bamital.G.
Alert level: severe
Updated on Oct 25, 2010
Virus:Win32/Bamital.G is the detection for the files "explorer.exe" and "winlogon.exe" when they are infected. The infection is caused by TrojanDropper:Win32/Bamital.C.
Alert level: severe
Updated on Nov 11, 2010
Virus:Win32/Bamital.H is the detection for the files "explorer.exe" and "winlogon.exe" when they are infected. The infection is caused by TrojanDropper:Win32/Bamital.C.
Alert level: severe
Updated on Nov 19, 2010
Trojan:Win32/Oficla.AC is a trojan that attempts to contact a remote server to download and execute arbitrary files. In the wild, it has been observed downloading TrojanDropper:Win32/Bamital.C, which in turn infects the compromised system with Virus:Win32/Bamital.C.
Alert level: severe
Updated on Jan 20, 2011
Trojan:Win32/Bamital.I is a trojan that may redirect user search requests to other sites. It also disables System Restore.
Alert level: severe
Updated on Feb 09, 2011
Trojan:Win32/Bamital.J is a component of the Win32/Bamital trojan family. The trojan runs other components that are used to intercept web browser traffic and redirect web search queries.
Alert level: severe
Updated on May 27, 2011

Trojan:Win32/Bamital.N is the detection for malware that intercepts web browser traffic and redirects search engine results. It also redirects access to certain websites to the local host.

Alert level: severe
Updated on Feb 15, 2011
Alert level: severe