Sophos

Troj/Banker-EKU

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 5 February 2008 05:40:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Banker-EKU is a Trojan for the Windows platform.

Troj/Banker-EKU includes functionality to send notification messages to remote locations.

When Troj/Banker-EKU is installed the following files are created:

<Startup>\iexplore.exe
<System>\reg_0001.txt

The file iexplore.exe is detected as Mal/Banspy-G. The file reg_0001.txt is not malicious and may be deleted.

Troj/Banker-EKU sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IEXPLORE
C:\Arquivos de programas\IEXPLORE.EXE

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer