Troj/Banker-GD is a password stealing Trojan for the Windows platform.
Troj/Banker-GD targets the customers of certain Brazilian online banking websites by monitoring browser activity and taking screengrabs.
Troj/Banker-GD is a password stealing Trojan for the Windows platform.
Troj/Banker-GD targets the customers of certain Brazilian online banking websites by monitoring browser activity and taking screengrabs.
When first run Troj/Banker-GD copies itself to <Windows>\wscntfy.exe.
The following registry entry is created to run wscntfy.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KAVPersonal90
<Windows>\wscntfy.exe /nosplash