Troj/Bancban-CK is password stealing Trojan targeted at customers of
banks, in particular those based in Brazil.
The Trojan attempts to fetch a keylogging component from a remote website and save it as keylogf.dll in to the Windows system folder.
Troj/Bancban-CK creates the following registry entry in an attempt to have it run on system start up.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
dark =
<path to the Windows system32 folder>\imgst.scr