Troj/Banker-DF is a password stealing Trojan for the Windows platform.
The Trojan monitors a user's internet activity and displays fake login screens for a number of Brazilian onling banking websites. The Trojan records the user's login details and emails them to a remote address.
The Trojan creates the following registry entry to ensure that is is run each time a user logs on :
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msbsc
<Path to Trojan>