Sophos

Sophos blogs

Troj/Bancban-AI

Aliases
  • Trojan-Spy.Win32.Banbra.y
  • PWS-Bancban.gen.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 November 2004 17:41:03 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bancban-AI is a password-stealing Trojan related to certain Brazilian banking websites. In particular, the Trojan attempts to steal data relating to the following banks:

Banco do Brasil
Banco Bradesco
Caixa Economica
Banco ITAU

Troj/Bancban-AI runs in the background and monitors the title bar of Internet Explorer for text relating to banking websites. When the user attempts to access such sites, the Trojan is able to display its own user interface, in order to persuade the user to enter banking details. Stolen data is sent by email to a remote user.

In order to run itself on system startup, the Trojan creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<Trojan name without file extension>
<Trojan filename including path>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer