Sophos

Troj/Bancj-A

Aliases
  • Trojan-Spy.Win32.Banbra.bi
  • PWSteal.Banpaes
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 29 August 2005 14:24:15 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bancj-A is a password-stealing Trojan for the Windows platform.

Troj/Bancj-A monitors browser activity for visits to specific banking websites. On detecting such activity, the Trojan displays a fake login page and records keystrokes in an attempt to steal login details. Any information stolen in this manner is submitted to the author by email.

When the Trojan is installed it creates the file %SYSTEM%\imgit.txt. This file can be deleted.

The following registry entry is created to run Troj/Bancj-A on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
imgit

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer