Troj/Bancban-AI

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Bancban-AI is a password-stealing Trojan related to certain Brazilian banking websites. In particular, the Trojan attempts to steal data relating to the following banks:

Banco do Brasil
Banco Bradesco
Caixa Economica
Banco ITAU

Troj/Bancban-AI runs in the background and monitors the title bar of Internet Explorer for text relating to banking websites. When the user attempts to access such sites, the Trojan is able to display its own user interface, in order to persuade the user to enter banking details. Stolen data is sent by email to a remote user.

In order to run itself on system startup, the Trojan creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<Trojan name without file extension>
<Trojan filename including path>

download Try Sophos products for free
Download now