Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 3 March 2005 14:07:45 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bancban-BQ is a password stealing Trojan for the Windows platform.
Troj/Bancban-BQ copies itself to the Windows system folder as svchot.exe and creates the following registry entry to ensure it is run at system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
boot_reg
%SYSTEM%\svchot.exe
Troj/Bancban-BQ monitors which URLs are visited by the web browser and creates fake web pages for certain Brazilian banking sites in order to log account information. The logged information is sent to remote users via email.
