Troj/Banker-GI is a password stealing Trojan for the Windows platform.
Troj/Banker-GI targets the customers of certain Brazilian online banking websites by displaying fake interfaces and recording any details that are entered.
When Troj/Banker-GI is installed it creates the file <System>\IExplorer.exe, also detected as Troj/Banker-GI.
The following registry entry is created to run IExplorer.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Win_BooT
<Path to Trojan>