Sophos

Sophos blogs

Troj/Bancos-DX

Aliases
  • Trojan-Spy.Win32.Bancos.jh
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 29 August 2005 06:31:32 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bancos-DX is an Internet Banking Trojan for the Windows platform.

Troj/Bancos-DX monitors the user's internet activity and displays fake login pages if the user visits certain predefined URLs. Any login details entered on the fake page are logged.

When first run Troj/Bancos-DX copies itself to <System>\tasklist32.exe.

The following registry entries are created to run tasklist32.exe on startup:

HKLM\SOfTWARE\Microsoft\Windows\CurrentVersion\Run
TaskList
<System>\tasklist32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
TaskList
<System>\tasklist32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer